cpujul2024csaf
HIGH CVSS 7.3 csaf_oracle
Description
No description available.
Timeline
- Published
- 2024-07-16 13:00 UTC
- Last Modified
- 2024-09-18
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"document": {
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"publisher": {
"category": "vendor",
"name": "Oracle",
"namespace": "https://www.oracle.com"
},
"references": [
{
"summary": "URL to html version of Advisory",
"url": "https://www.oracle.com/security-alerts/cpujul2024.html"
},
{
"category": "self",
"summary": "URL to CSAF version of Advisory",
"url": "https://www.oracle.com/docs/tech/security-alerts/cpujul2024csaf.json"
}
],
"title": "Oracle Critical Patch Update Advisory - July 2024 - Oracle CSAF",
"tracking": {
"current_release_date": "2024-09-18T13:00:00-07:00",
"id": "CPUJul2024csaf",
"initial_release_date": "2024-07-16T13:00:00-07:00",
"revision_history": [
{
"date": "2024-07-16T13:00:00-07:00",
"number": "1",
"summary": "Initial Release"
},
{
"date": "2024-07-24T13:00:00-07:00",
"number": "2",
"summary": "Rev 2. Corrected additional CVE lists and updated credit"
},
{
"date": "2024-09-18T13:00:00-07:00",
"number": "3",
"summary": "Rev 3. Updated the affected versions for CGBU PI, Edge Protection Proxy and Oracle Insurance Policy Administration J2EE"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Analytics Desktop Version Prior to 7.7.0",
"product": {
"name": "Oracle Analytics Desktop Version Prior to 7.7.0",
"product_id": "P-2025V-Prior to 7.7.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:analytics_desktop:prior_to_7.7.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Analytics Desktop Version Prior to 7.8.0",
"product": {
"name": "Oracle Analytics Desktop Version Prior to 7.8.0",
"product_id": "P-2025V-Prior to 7.8.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:analytics_desktop:prior_to_7.8.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Analytics Desktop"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Business Intelligence Enterprise Edition(Analytics Server) Version 12.2.1.4.0",
"product": {
"name": "Oracle Business Intelligence Enterprise Edition(Analytics Server) Version 12.2.1.4.0",
"product_id": "P-2025(Analytics Server)V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Business Intelligence Enterprise Edition(BI Platform Security) Version 12.2.1.4.0",
"product": {
"name": "Oracle Business Intelligence Enterprise Edition(BI Platform Security) Version 12.2.1.4.0",
"product_id": "P-2025(BI Platform Security)V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
"product": {
"name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
"product_id": "P-2025V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Business Intelligence Enterprise Edition Version 7.0.0.0.0",
"product": {
"name": "Oracle Business Intelligence Enterprise Edition Version 7.0.0.0.0",
"product_id": "P-2025V-7.0.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:business_intelligence:7.0.0.0.0:*:*:*:enterprise:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0",
"product": {
"name": "Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0",
"product_id": "P-2025V-7.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:business_intelligence:7.6.0.0.0:*:*:*:enterprise:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Business Intelligence Enterprise Edition"
}
],
"category": "product_family",
"name": "Oracle Analytics"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Application Express Version 23.2",
"product": {
"name": "Oracle Application Express Version 23.2",
"product_id": "P-1348V-23.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:application_express:23.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Application Express"
}
],
"category": "product_family",
"name": "Oracle Application Express"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Big Data Spatial and Graph Version 3.0.6",
"product": {
"name": "Oracle Big Data Spatial and Graph Version 3.0.6",
"product_id": "P-11528V-3.0.6",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:big_data_spatial_and_graph:3.0.6:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Big Data Spatial and Graph"
}
],
"category": "product_family",
"name": "Oracle Big Data Spatial and Graph"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Commerce Guided Search Version 11.3.2",
"product": {
"name": "Oracle Commerce Guided Search Version 11.3.2",
"product_id": "P-9633V-11.3.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Commerce Guided Search"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Commerce Platform Version 11.3.0",
"product": {
"name": "Oracle Commerce Platform Version 11.3.0",
"product_id": "P-9348V-11.3.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:commerce_platform:11.3.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Commerce Platform Version 11.3.1",
"product": {
"name": "Oracle Commerce Platform Version 11.3.1",
"product_id": "P-9348V-11.3.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:commerce_platform:11.3.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Commerce Platform Version 11.3.2",
"product": {
"name": "Oracle Commerce Platform Version 11.3.2",
"product_id": "P-9348V-11.3.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:commerce_platform:11.3.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Commerce Platform"
}
],
"category": "product_family",
"name": "Oracle Commerce"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Automated Test Suite Version 23.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Automated Test Suite Version 23.1.0",
"product_id": "P-14488V-23.1.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:23.1.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Automated Test Suite Version 23.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Automated Test Suite Version 23.4.0",
"product_id": "P-14488V-23.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:23.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Automated Test Suite"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 23.4.0-23.4.3",
"product": {
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 23.4.0-23.4.3",
"product_id": "P-14121V-23.4.0-23.4.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:23.4.0-23.4.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Binding Support Function"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Console Version 23.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Console Version 23.4.0",
"product_id": "P-14250V-23.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_console:23.4.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Console Version 23.4.1",
"product": {
"name": "Oracle Communications Cloud Native Core Console Version 23.4.1",
"product_id": "P-14250V-23.4.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_console:23.4.1:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Console"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Data Analytics Function Version 24.2.0",
"product": {
"name": "Oracle Communications Cloud Native Core Network Data Analytics Function Version 24.2.0",
"product_id": "P-14489V-24.2.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_data_analytics_function:24.2.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Network Data Analytics Function"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Exposure Function Version 23.4.3",
"product": {
"name": "Oracle Communications Cloud Native Core Network Exposure Function Version 23.4.3",
"product_id": "P-14122V-23.4.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:23.4.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Network Exposure Function"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 23.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 23.4.0",
"product_id": "P-14125V-23.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:23.4.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 24.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 24.1.0",
"product_id": "P-14125V-24.1.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:24.1.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Repository Function Version 23.4.2",
"product": {
"name": "Oracle Communications Cloud Native Core Network Repository Function Version 23.4.2",
"product_id": "P-14118V-23.4.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:23.4.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Network Repository Function"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Policy Version 23.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Policy Version 23.4.0",
"product_id": "P-14277V-23.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:23.4.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Cloud Native Core Policy Version 23.4.0-23.4.4",
"product": {
"name": "Oracle Communications Cloud Native Core Policy Version 23.4.0-23.4.4",
"product_id": "P-14277V-23.4.0-23.4.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:23.4.0-23.4.4:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Policy"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 23.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 23.4.0",
"product_id": "P-14123V-23.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:23.4.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.1.0",
"product_id": "P-14123V-24.1.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:24.1.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 23.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 23.4.0",
"product_id": "P-14117V-23.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:23.4.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 23.4.1",
"product": {
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 23.4.1",
"product_id": "P-14117V-23.4.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:23.4.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 23.4.2",
"product": {
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 23.4.2",
"product_id": "P-14117V-23.4.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:23.4.2:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 24.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 24.1.0",
"product_id": "P-14117V-24.1.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:24.1.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Service Communication Proxy"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Unified Data Repository Version 23.4.1",
"product": {
"name": "Oracle Communications Cloud Native Core Unified Data Repository Version 23.4.1",
"product_id": "P-14119V-23.4.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:23.4.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Unified Data Repository Version 23.4.2",
"product": {
"name": "Oracle Communications Cloud Native Core Unified Data Repository Version 23.4.2",
"product_id": "P-14119V-23.4.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:23.4.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Unified Data Repository"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Diameter Signaling Router Version 8.6.0.4-8.6.0.6",
"product": {
"name": "Oracle Communications Diameter Signaling Router Version 8.6.0.4-8.6.0.6",
"product_id": "P-10899V-8.6.0.4-8.6.0.6",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:8.6.0.4-8.6.0.6:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Diameter Signaling Router Version 8.6.0.4-8.6.0.8",
"product": {
"name": "Oracle Communications Diameter Signaling Router Version 8.6.0.4-8.6.0.8",
"product_id": "P-10899V-8.6.0.4-8.6.0.8",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:8.6.0.4-8.6.0.8:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Diameter Signaling Router"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications EAGLE Element Management System Version 46.6.4",
"product": {
"name": "Oracle Communications EAGLE Element Management System Version 46.6.4",
"product_id": "P-11125V-46.6.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_eagle_element_management_system:46.6.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications EAGLE Element Management System Version 46.6.5",
"product": {
"name": "Oracle Communications EAGLE Element Management System Version 46.6.5",
"product_id": "P-11125V-46.6.5",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_eagle_element_management_system:46.6.5:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications EAGLE Element Management System"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Element Manager Version 9.0.0-9.0.3",
"product": {
"name": "Oracle Communications Element Manager Version 9.0.0-9.0.3",
"product_id": "P-11052V-9.0.0-9.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_element_manager:9.0.0-9.0.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Element Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Network Analytics Data Director Version 23.4.0",
"product": {
"name": "Oracle Communications Network Analytics Data Director Version 23.4.0",
"product_id": "P-14547V-23.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:23.4.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Network Analytics Data Director Version 24.1.0",
"product": {
"name": "Oracle Communications Network Analytics Data Director Version 24.1.0",
"product_id": "P-14547V-24.1.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.1.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Network Analytics Data Director"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Operations Monitor Version 5.1",
"product": {
"name": "Oracle Communications Operations Monitor Version 5.1",
"product_id": "P-10761V-5.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_operations_monitor:5.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Operations Monitor Version 5.2",
"product": {
"name": "Oracle Communications Operations Monitor Version 5.2",
"product_id": "P-10761V-5.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_operations_monitor:5.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Operations Monitor"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Performance Intelligence Version 10.4.0.4.3 and prior",
"product": {
"name": "Oracle Communications Performance Intelligence Version 10.4.0.4.3 and prior",
"product_id": "P-11044V-10.4.0.4.3 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_performance_intelligence:10.5:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Performance Intelligence"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Policy Management Version 12.6.1.0.0",
"product": {
"name": "Oracle Communications Policy Management Version 12.6.1.0.0",
"product_id": "P-10900V-12.6.1.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_policy_management:12.6.1.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Policy Management Version 15.0.0.0.0",
"product": {
"name": "Oracle Communications Policy Management Version 15.0.0.0.0",
"product_id": "P-10900V-15.0.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_policy_management:15.0.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Policy Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Session Border Controller Version 4.1.0",
"product": {
"name": "Oracle Communications Session Border Controller Version 4.1.0",
"product_id": "P-10750V-4.1.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_session_border_controller:4.1.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Session Border Controller Version 4.2.0",
"product": {
"name": "Oracle Communications Session Border Controller Version 4.2.0",
"product_id": "P-10750V-4.2.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_session_border_controller:4.2.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Session Border Controller Version 9.2.0",
"product": {
"name": "Oracle Communications Session Border Controller Version 9.2.0",
"product_id": "P-10750V-9.2.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.2.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Session Border Controller Version 9.3.0",
"product": {
"name": "Oracle Communications Session Border Controller Version 9.3.0",
"product_id": "P-10750V-9.3.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.3.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Session Border Controller"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Session Report Manager Version 9.0.0-9.0.3",
"product": {
"name": "Oracle Communications Session Report Manager Version 9.0.0-9.0.3",
"product_id": "P-10770V-9.0.0-9.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_session_report_manager:9.0.0-9.0.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Session Report Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications User Data Repository Version 12.11.0",
"product": {
"name": "Oracle Communications User Data Repository Version 12.11.0",
"product_id": "P-11108V-12.11.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_user_data_repository:12.11.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications User Data Repository Version 12.11.3",
"product": {
"name": "Oracle Communications User Data Repository Version 12.11.3",
"product_id": "P-11108V-12.11.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_user_data_repository:12.11.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications User Data Repository Version 12.11.4",
"product": {
"name": "Oracle Communications User Data Repository Version 12.11.4",
"product_id": "P-11108V-12.11.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_user_data_repository:12.11.4:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications User Data Repository"
}
],
"category": "product_family",
"name": "Oracle Communications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications ASAP Version 7.4",
"product": {
"name": "Oracle Communications ASAP Version 7.4",
"product_id": "P-2260V-7.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_asap:7.4:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications ASAP"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications BRM - Elastic Charging Engine Version 12.0.0.4-12.0.0.8",
"product": {
"name": "Oracle Communications BRM - Elastic Charging Engine Version 12.0.0.4-12.0.0.8",
"product_id": "P-9742V-12.0.0.4-12.0.0.8",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.4-12.0.0.8:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0",
"product": {
"name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0",
"product_id": "P-9742V-15.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications BRM - Elastic Charging Engine"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Billing and Revenue Management Version 12.0.0.4.0-12.0.0.8.0",
"product": {
"name": "Oracle Communications Billing and Revenue Management Version 12.0.0.4.0-12.0.0.8.0",
"product_id": "P-2136V-12.0.0.4.0-12.0.0.8.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.4.0-12.0.0.8.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Billing and Revenue Management Version 15.0.0.0.0",
"product": {
"name": "Oracle Communications Billing and Revenue Management Version 15.0.0.0.0",
"product_id": "P-2136V-15.0.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Billing and Revenue Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Converged Charging System Version 2.0.0.0.0",
"product": {
"name": "Oracle Communications Converged Charging System Version 2.0.0.0.0",
"product_id": "P-14565V-2.0.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_converged_charging_system:2.0.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Converged Charging System Version 2.0.0.1.0",
"product": {
"name": "Oracle Communications Converged Charging System Version 2.0.0.1.0",
"product_id": "P-14565V-2.0.0.1.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_converged_charging_system:2.0.0.1.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Converged Charging System"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.6.0.0",
"product": {
"name": "Oracle Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.6.0.0",
"product_id": "P-12985V-12.0.1.0.0-12.0.6.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:12.0.1.0.0-12.0.6.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Convergent Charging Controller Version 15.0.0.0.0",
"product": {
"name": "Oracle Communications Convergent Charging Controller Version 15.0.0.0.0",
"product_id": "P-12985V-15.0.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:15.0.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Convergent Charging Controller Version 6.0.1.0.0",
"product": {
"name": "Oracle Communications Convergent Charging Controller Version 6.0.1.0.0",
"product_id": "P-12985V-6.0.1.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:6.0.1.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Convergent Charging Controller"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Network Charging and Control Version 12.0.1.0.0-12.0.6.0.0",
"product": {
"name": "Oracle Communications Network Charging and Control Version 12.0.1.0.0-12.0.6.0.0",
"product_id": "P-4623V-12.0.1.0.0-12.0.6.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.1.0.0-12.0.6.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Network Charging and Control Version 15.0.0.0.0",
"product": {
"name": "Oracle Communications Network Charging and Control Version 15.0.0.0.0",
"product_id": "P-4623V-15.0.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:15.0.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Network Charging and Control Version 6.0.1.0.0",
"product": {
"name": "Oracle Communications Network Charging and Control Version 6.0.1.0.0",
"product_id": "P-4623V-6.0.1.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Network Charging and Control"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Pricing Design Center Version 12.0.0.4.0-12.0.0.8.0",
"product": {
"name": "Oracle Communications Pricing Design Center Version 12.0.0.4.0-12.0.0.8.0",
"product_id": "P-9437V-12.0.0.4.0-12.0.0.8.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.4.0-12.0.0.8.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Pricing Design Center Version 15.0.0.0.0",
"product": {
"name": "Oracle Communications Pricing Design Center Version 15.0.0.0.0",
"product_id": "P-9437V-15.0.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.0.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Pricing Design Center"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Service Catalog and Design Version 7.4.0-7.4.2",
"product": {
"name": "Oracle Communications Service Catalog and Design Version 7.4.0-7.4.2",
"product_id": "P-2283V-7.4.0-7.4.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:7.4.0-7.4.2:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Service Catalog and Design Version 8.0.0",
"product": {
"name": "Oracle Communications Service Catalog and Design Version 8.0.0",
"product_id": "P-2283V-8.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Service Catalog and Design"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Unified Assurance Version 5.5.0-5.5.21",
"product": {
"name": "Oracle Communications Unified Assurance Version 5.5.0-5.5.21",
"product_id": "P-14597V-5.5.0-5.5.21",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_unified_assurance:5.5.0-5.5.21:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Unified Assurance Version 6.0.0-6.0.4",
"product": {
"name": "Oracle Communications Unified Assurance Version 6.0.0-6.0.4",
"product_id": "P-14597V-6.0.0-6.0.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.0.0-6.0.4:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Unified Assurance"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Unified Inventory Management Version 7.4.1",
"product": {
"name": "Oracle Communications Unified Inventory Management Version 7.4.1",
"product_id": "P-4516V-7.4.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Communications Unified Inventory Management Version 7.4.2",
"product": {
"name": "Oracle Communications Unified Inventory Management Version 7.4.2",
"product_id": "P-4516V-7.4.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Communications Unified Inventory Management"
}
],
"category": "product_family",
"name": "Oracle Communications Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Primavera Gateway Version 19.12.0-19.12.19",
"product": {
"name": "Primavera Gateway Version 19.12.0-19.12.19",
"product_id": "P-10605V-19.12.0-19.12.19",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:primavera_gateway:19.12.0-19.12.19:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Primavera Gateway Version 20.12.0-20.12.14",
"product": {
"name": "Primavera Gateway Version 20.12.0-20.12.14",
"product_id": "P-10605V-20.12.0-20.12.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:primavera_gateway:20.12.0-20.12.14:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Primavera Gateway Version 21.12.0-21.12.12",
"product": {
"name": "Primavera Gateway Version 21.12.0-21.12.12",
"product_id": "P-10605V-21.12.0-21.12.12",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:primavera_gateway:21.12.0-21.12.12:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Primavera Gateway"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Primavera Unifier Version 19.12.0-19.12.16",
"product": {
"name": "Primavera Unifier Version 19.12.0-19.12.16",
"product_id": "P-10354V-19.12.0-19.12.16",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:primavera_unifier:19.12.0-19.12.16:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Primavera Unifier Version 20.12.0-20.12.16",
"product": {
"name": "Primavera Unifier Version 20.12.0-20.12.16",
"product_id": "P-10354V-20.12.0-20.12.16",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:primavera_unifier:20.12.0-20.12.16:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Primavera Unifier Version 21.12.0-21.12.17",
"product": {
"name": "Primavera Unifier Version 21.12.0-21.12.17",
"product_id": "P-10354V-21.12.0-21.12.17",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:primavera_unifier:21.12.0-21.12.17:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Primavera Unifier Version 22.12.0-22.12.13",
"product": {
"name": "Primavera Unifier Version 22.12.0-22.12.13",
"product_id": "P-10354V-22.12.0-22.12.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:primavera_unifier:22.12.0-22.12.13:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Primavera Unifier Version 23.12.0-23.12.6",
"product": {
"name": "Primavera Unifier Version 23.12.0-23.12.6",
"product_id": "P-10354V-23.12.0-23.12.6",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:primavera_unifier:23.12.0-23.12.6:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Primavera Unifier"
}
],
"category": "product_family",
"name": "Oracle Construction and Engineering"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Fleet Patching and Provisioning Version 23.4",
"product": {
"name": "Fleet Patching and Provisioning Version 23.4",
"product_id": "P-14599V-23.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:fleet_patching_and_provisioning:23.4:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Fleet Patching and Provisioning"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Database Server(Oracle Database Core) Version 19.20-19.23",
"product": {
"name": "Oracle Database Server(Oracle Database Core) Version 19.20-19.23",
"product_id": "P-5(Oracle Database Core)V-19.20-19.23",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_core:19.20-19.23:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Java VM) Version 19.3-19.23",
"product": {
"name": "Oracle Database Server(Java VM) Version 19.3-19.23",
"product_id": "P-5(Java VM)V-19.3-19.23",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_java_vm:19.3-19.23:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Oracle Database Core) Version 19.3-19.23",
"product": {
"name": "Oracle Database Server(Oracle Database Core) Version 19.3-19.23",
"product_id": "P-5(Oracle Database Core)V-19.3-19.23",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_core:19.3-19.23:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Oracle Database Portable Clusterware) Version 19.3-19.23",
"product": {
"name": "Oracle Database Server(Oracle Database Portable Clusterware) Version 19.3-19.23",
"product_id": "P-5(Oracle Database Portable Clusterware)V-19.3-19.23",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_portable_clusterware:19.3-19.23:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Oracle Database RDBMS Security) Version 19.3-19.23",
"product": {
"name": "Oracle Database Server(Oracle Database RDBMS Security) Version 19.3-19.23",
"product_id": "P-5(Oracle Database RDBMS Security)V-19.3-19.23",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_rdbms_security:19.3-19.23:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Oracle Database Core) Version 21.11-21.14",
"product": {
"name": "Oracle Database Server(Oracle Database Core) Version 21.11-21.14",
"product_id": "P-5(Oracle Database Core)V-21.11-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_core:21.11-21.14:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Java VM) Version 21.3-21.14",
"product": {
"name": "Oracle Database Server(Java VM) Version 21.3-21.14",
"product_id": "P-5(Java VM)V-21.3-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_java_vm:21.3-21.14:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Multilingual Engine) Version 21.3-21.14",
"product": {
"name": "Oracle Database Server(Multilingual Engine) Version 21.3-21.14",
"product_id": "P-5(Multilingual Engine)V-21.3-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_multilingual_engine:21.3-21.14:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(OML4Py) Version 21.3-21.14",
"product": {
"name": "Oracle Database Server(OML4Py) Version 21.3-21.14",
"product_id": "P-5(OML4Py)V-21.3-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_oml4py:21.3-21.14:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Oracle Database Core) Version 21.3-21.14",
"product": {
"name": "Oracle Database Server(Oracle Database Core) Version 21.3-21.14",
"product_id": "P-5(Oracle Database Core)V-21.3-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_core:21.3-21.14:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Oracle Database Portable Clusterware) Version 21.3-21.14",
"product": {
"name": "Oracle Database Server(Oracle Database Portable Clusterware) Version 21.3-21.14",
"product_id": "P-5(Oracle Database Portable Clusterware)V-21.3-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_portable_clusterware:21.3-21.14:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Database Server(Oracle Database Workload Manager) Version 21.3-21.14",
"product": {
"name": "Oracle Database Server(Oracle Database Workload Manager) Version 21.3-21.14",
"product_id": "P-5(Oracle Database Workload Manager)V-21.3-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_workload_manager:21.3-21.14:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Java VM) Version 23.4",
"product": {
"name": "Oracle Database Server(Java VM) Version 23.4",
"product_id": "P-5(Java VM)V-23.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_java_vm:23.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Multilingual Engine) Version 23.4",
"product": {
"name": "Oracle Database Server(Multilingual Engine) Version 23.4",
"product_id": "P-5(Multilingual Engine)V-23.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_multilingual_engine:23.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Database Server(OML4Py) Version 23.4",
"product": {
"name": "Oracle Database Server(OML4Py) Version 23.4",
"product_id": "P-5(OML4Py)V-23.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_oml4py:23.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Oracle Database Core) Version 23.4",
"product": {
"name": "Oracle Database Server(Oracle Database Core) Version 23.4",
"product_id": "P-5(Oracle Database Core)V-23.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:database_-_core:23.4:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Database Server"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Spatial and Graph Version 19.3-19.23",
"product": {
"name": "Oracle Spatial and Graph Version 19.3-19.23",
"product_id": "P-619V-19.3-19.23",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:spatial_and_graph:19.3-19.23:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Spatial and Graph Version 21.3-21.14",
"product": {
"name": "Oracle Spatial and Graph Version 21.3-21.14",
"product_id": "P-619V-21.3-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:spatial_and_graph:21.3-21.14:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Spatial and Graph"
}
],
"category": "product_family",
"name": "Oracle Database Server"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Application Object Library Version 12.2.6-12.2.13",
"product": {
"name": "Oracle Application Object Library Version 12.2.6-12.2.13",
"product_id": "P-510V-12.2.6-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:application_object_library:12.2.6-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Application Object Library"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Applications Framework Version 12.2.3-12.2.13",
"product": {
"name": "Oracle Applications Framework Version 12.2.3-12.2.13",
"product_id": "P-1472V-12.2.3-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:applications_framework:12.2.3-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Applications Framework"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Enterprise Asset Management Version 12.2.11-12.2.13",
"product": {
"name": "Oracle Enterprise Asset Management Version 12.2.11-12.2.13",
"product_id": "P-1142V-12.2.11-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:enterprise_asset_management:12.2.11-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Enterprise Asset Management"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Marketing Version 12.2.3-12.2.13",
"product": {
"name": "Oracle Marketing Version 12.2.3-12.2.13",
"product_id": "P-229V-12.2.3-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:marketing:12.2.3-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Marketing"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Process Manufacturing Financials Version 12.2.12-12.2.13",
"product": {
"name": "Oracle Process Manufacturing Financials Version 12.2.12-12.2.13",
"product_id": "P-736V-12.2.12-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:process_manufacturing_financials:12.2.12-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Process Manufacturing Financials"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Process Manufacturing Product Development Version 12.2.13",
"product": {
"name": "Oracle Process Manufacturing Product Development Version 12.2.13",
"product_id": "P-744V-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:process_manufacturing_product_development:12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Process Manufacturing Product Development"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Purchasing Version 12.2.3-12.2.13",
"product": {
"name": "Oracle Purchasing Version 12.2.3-12.2.13",
"product_id": "P-502V-12.2.3-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:purchasing:12.2.3-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Purchasing"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Trade Management Version 12.2.3-12.2.13",
"product": {
"name": "Oracle Trade Management Version 12.2.3-12.2.13",
"product_id": "P-765V-12.2.3-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:trade_management:12.2.3-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Trade Management"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Trading Community Version 12.2.3-12.2.13",
"product": {
"name": "Oracle Trading Community Version 12.2.3-12.2.13",
"product_id": "P-1137V-12.2.3-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:trading_community:12.2.3-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Trading Community"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle iStore Version 12.2.3-12.2.13",
"product": {
"name": "Oracle iStore Version 12.2.3-12.2.13",
"product_id": "P-384V-12.2.3-12.2.13",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:istore:12.2.3-12.2.13:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle iStore"
}
],
"category": "product_family",
"name": "Oracle E-Business Suite"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Application Testing Suite Version 13.3.0.1",
"product": {
"name": "Oracle Application Testing Suite Version 13.3.0.1",
"product_id": "P-4622V-13.3.0.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Application Testing Suite"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Enterprise Manager Base Platform Version 13.5.0.0",
"product": {
"name": "Oracle Enterprise Manager Base Platform Version 13.5.0.0",
"product_id": "P-1370V-13.5.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Enterprise Manager Base Platform"
}
],
"category": "product_family",
"name": "Oracle Enterprise Manager"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Essbase Version 21.5.6",
"product": {
"name": "Oracle Essbase Version 21.5.6",
"product_id": "P-4379V-21.5.6",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:essbase:21.5.6:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Essbase"
}
],
"category": "product_family",
"name": "Oracle Essbase"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Branch Version 14.4.0.0.0",
"product": {
"name": "Oracle Banking Branch Version 14.4.0.0.0",
"product_id": "P-14324V-14.4.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_branch:14.4.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Branch Version 14.5.0.0.0",
"product": {
"name": "Oracle Banking Branch Version 14.5.0.0.0",
"product_id": "P-14324V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_branch:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Branch Version 14.6.0.0.0",
"product": {
"name": "Oracle Banking Branch Version 14.6.0.0.0",
"product_id": "P-14324V-14.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_branch:14.6.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Branch Version 14.7.0.0.0",
"product": {
"name": "Oracle Banking Branch Version 14.7.0.0.0",
"product_id": "P-14324V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_branch:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Branch"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Cash Management Version 14.4.0.0.0",
"product": {
"name": "Oracle Banking Cash Management Version 14.4.0.0.0",
"product_id": "P-14195V-14.4.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_cash_management:14.4.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Cash Management Version 14.5.0.0.0",
"product": {
"name": "Oracle Banking Cash Management Version 14.5.0.0.0",
"product_id": "P-14195V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_cash_management:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Cash Management Version 14.6.0.0.0",
"product": {
"name": "Oracle Banking Cash Management Version 14.6.0.0.0",
"product_id": "P-14195V-14.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_cash_management:14.6.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Cash Management Version 14.7.0.0.0",
"product": {
"name": "Oracle Banking Cash Management Version 14.7.0.0.0",
"product_id": "P-14195V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_cash_management:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Cash Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Corporate Lending Process Management Version 14.4.0.0.0",
"product": {
"name": "Oracle Banking Corporate Lending Process Management Version 14.4.0.0.0",
"product_id": "P-13701V-14.4.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.4.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Corporate Lending Process Management Version 14.5.0.0.0",
"product": {
"name": "Oracle Banking Corporate Lending Process Management Version 14.5.0.0.0",
"product_id": "P-13701V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Corporate Lending Process Management Version 14.6.0.0.0",
"product": {
"name": "Oracle Banking Corporate Lending Process Management Version 14.6.0.0.0",
"product_id": "P-13701V-14.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.6.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Corporate Lending Process Management Version 14.7.0.0.0",
"product": {
"name": "Oracle Banking Corporate Lending Process Management Version 14.7.0.0.0",
"product_id": "P-13701V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Corporate Lending Process Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Credit Facilities Process Management Version 14.5.0.0.0",
"product": {
"name": "Oracle Banking Credit Facilities Process Management Version 14.5.0.0.0",
"product_id": "P-13703V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Credit Facilities Process Management Version 14.6.0.0.0",
"product": {
"name": "Oracle Banking Credit Facilities Process Management Version 14.6.0.0.0",
"product_id": "P-13703V-14.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.6.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Credit Facilities Process Management Version 14.7.0.0.0",
"product": {
"name": "Oracle Banking Credit Facilities Process Management Version 14.7.0.0.0",
"product_id": "P-13703V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Credit Facilities Process Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Deposits and Lines of Credit Servicing Version 2.12.0.0.0",
"product": {
"name": "Oracle Banking Deposits and Lines of Credit Servicing Version 2.12.0.0.0",
"product_id": "P-13928V-2.12.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_deposits_and_lines_of_credit_servicing:2.12.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Deposits and Lines of Credit Servicing"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Liquidity Management Version 14.5.0.0.0",
"product": {
"name": "Oracle Banking Liquidity Management Version 14.5.0.0.0",
"product_id": "P-13304V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Liquidity Management Version 14.6.0.0.0",
"product": {
"name": "Oracle Banking Liquidity Management Version 14.6.0.0.0",
"product_id": "P-13304V-14.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.6.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Liquidity Management Version 14.7.0.0.0",
"product": {
"name": "Oracle Banking Liquidity Management Version 14.7.0.0.0",
"product_id": "P-13304V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Liquidity Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Origination Version 14.5.0.0.0",
"product": {
"name": "Oracle Banking Origination Version 14.5.0.0.0",
"product_id": "P-14325V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_origination:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Origination Version 14.6.0.0.0",
"product": {
"name": "Oracle Banking Origination Version 14.6.0.0.0",
"product_id": "P-14325V-14.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_origination:14.6.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Origination Version 14.7.0.0.0",
"product": {
"name": "Oracle Banking Origination Version 14.7.0.0.0",
"product_id": "P-14325V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_origination:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Origination"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Party Management Version 2.7.0.0.0",
"product": {
"name": "Oracle Banking Party Management Version 2.7.0.0.0",
"product_id": "P-13929V-2.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_party_management:2.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Party Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Platform Version 2.4.0.0.0",
"product": {
"name": "Oracle Banking Platform Version 2.4.0.0.0",
"product_id": "P-9178V-2.4.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_platform:2.4.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Platform"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Virtual Account Management Version 14.5.0.0.0",
"product": {
"name": "Oracle Banking Virtual Account Management Version 14.5.0.0.0",
"product_id": "P-13487V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Virtual Account Management Version 14.6.0.0.0",
"product": {
"name": "Oracle Banking Virtual Account Management Version 14.6.0.0.0",
"product_id": "P-13487V-14.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_virtual_account_management:14.6.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Banking Virtual Account Management Version 14.7.0.0.0",
"product": {
"name": "Oracle Banking Virtual Account Management Version 14.7.0.0.0",
"product_id": "P-13487V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:banking_virtual_account_management:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Banking Virtual Account Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle FLEXCUBE Investor Servicing Version 14.5.0.0.0",
"product": {
"name": "Oracle FLEXCUBE Investor Servicing Version 14.5.0.0.0",
"product_id": "P-9099V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:flexcube_investor_servicing:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle FLEXCUBE Investor Servicing Version 14.7.0.0.0",
"product": {
"name": "Oracle FLEXCUBE Investor Servicing Version 14.7.0.0.0",
"product_id": "P-9099V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:flexcube_investor_servicing:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle FLEXCUBE Investor Servicing"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle FLEXCUBE Universal Banking Version 14.5.0.0.0",
"product": {
"name": "Oracle FLEXCUBE Universal Banking Version 14.5.0.0.0",
"product_id": "P-9052V-14.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:flexcube_universal_banking:14.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle FLEXCUBE Universal Banking Version 14.6.0.0.0",
"product": {
"name": "Oracle FLEXCUBE Universal Banking Version 14.6.0.0.0",
"product_id": "P-9052V-14.6.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:flexcube_universal_banking:14.6.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle FLEXCUBE Universal Banking Version 14.7.0.0.0",
"product": {
"name": "Oracle FLEXCUBE Universal Banking Version 14.7.0.0.0",
"product_id": "P-9052V-14.7.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:flexcube_universal_banking:14.7.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle FLEXCUBE Universal Banking"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7",
"product_id": "P-5680V-8.0.7",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8",
"product_id": "P-5680V-8.0.8",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1",
"product_id": "P-5680V-8.1.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2",
"product_id": "P-5680V-8.1.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Analytical Applications Infrastructure"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Basel Regulatory Capital Basic Version 8.0.7.3",
"product": {
"name": "Oracle Financial Services Basel Regulatory Capital Basic Version 8.0.7.3",
"product_id": "P-9612V-8.0.7.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:8.0.7.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Basel Regulatory Capital Basic Version 8.0.8.3",
"product": {
"name": "Oracle Financial Services Basel Regulatory Capital Basic Version 8.0.8.3",
"product_id": "P-9612V-8.0.8.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:8.0.8.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Basel Regulatory Capital Basic"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 8.0.7.3",
"product": {
"name": "Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 8.0.7.3",
"product_id": "P-9450V-8.0.7.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:8.0.7.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 8.0.8.3",
"product": {
"name": "Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 8.0.8.3",
"product_id": "P-9450V-8.0.8.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:8.0.8.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Behavior Detection Platform Version 8.0.8.1",
"product": {
"name": "Oracle Financial Services Behavior Detection Platform Version 8.0.8.1",
"product_id": "P-9190V-8.0.8.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.8.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.1.1",
"product": {
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.1.1",
"product_id": "P-9190V-8.1.1.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.6",
"product": {
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.6",
"product_id": "P-9190V-8.1.2.6",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.6:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.7",
"product": {
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.7",
"product_id": "P-9190V-8.1.2.7",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.7:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Behavior Detection Platform"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Compliance Studio Version 8.1.2.6",
"product": {
"name": "Oracle Financial Services Compliance Studio Version 8.1.2.6",
"product_id": "P-14392V-8.1.2.6",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_compliance_studio:8.1.2.6:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Compliance Studio Version 8.1.2.7",
"product": {
"name": "Oracle Financial Services Compliance Studio Version 8.1.2.7",
"product_id": "P-14392V-8.1.2.7",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_compliance_studio:8.1.2.7:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Compliance Studio"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Case Management Version 8.0.8.2.8",
"product": {
"name": "Oracle Financial Services Enterprise Case Management Version 8.0.8.2.8",
"product_id": "P-13545V-8.0.8.2.8",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.8.2.8:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.1.1.18",
"product": {
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.1.1.18",
"product_id": "P-13545V-8.1.1.1.18",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.1.18:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.6.4",
"product": {
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.6.4",
"product_id": "P-13545V-8.1.2.6.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.6.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.7.3",
"product": {
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.7.3",
"product_id": "P-13545V-8.1.2.7.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.7.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Enterprise Case Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Model Management and Governance Version 8.1.2.5",
"product": {
"name": "Oracle Financial Services Model Management and Governance Version 8.1.2.5",
"product_id": "P-14276V-8.1.2.5",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.2.5:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Model Management and Governance Version 8.1.2.6",
"product": {
"name": "Oracle Financial Services Model Management and Governance Version 8.1.2.6",
"product_id": "P-14276V-8.1.2.6",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.2.6:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Model Management and Governance"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 6.0.0.0.0",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 6.0.0.0.0",
"product_id": "P-5322V-6.0.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_revenue_management_and_billing:6.0.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 6.1.0.0.0",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 6.1.0.0.0",
"product_id": "P-5322V-6.1.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_revenue_management_and_billing:6.1.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Revenue Management and Billing"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8.0",
"product": {
"name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8.0",
"product_id": "P-13789V-8.0.8.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.8.0:*:*:*:enterprise:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition"
}
],
"category": "product_family",
"name": "Oracle Financial Services Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Access Manager Version 12.2.1.4.0",
"product": {
"name": "Oracle Access Manager Version 12.2.1.4.0",
"product_id": "P-5565V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Access Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Business Activity Monitoring Version 12.2.1.4.0",
"product": {
"name": "Oracle Business Activity Monitoring Version 12.2.1.4.0",
"product_id": "P-1675V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:business_activity_monitoring:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Business Activity Monitoring"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Coherence Version 12.2.1.4.0",
"product": {
"name": "Oracle Coherence Version 12.2.1.4.0",
"product_id": "P-2545V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Coherence Version 14.1.1.0.0",
"product": {
"name": "Oracle Coherence Version 14.1.1.0.0",
"product_id": "P-2545V-14.1.1.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Coherence"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Data Integrator Version 12.2.1.4.0",
"product": {
"name": "Oracle Data Integrator Version 12.2.1.4.0",
"product_id": "P-2196V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Data Integrator"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Enterprise Data Quality Version 12.2.1.4.0",
"product": {
"name": "Oracle Enterprise Data Quality Version 12.2.1.4.0",
"product_id": "P-9464V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:enterprise_data_quality:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Enterprise Data Quality"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Fusion Middleware Version 12.2.1.4.0",
"product": {
"name": "Oracle Fusion Middleware Version 12.2.1.4.0",
"product_id": "P-1032V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Fusion Middleware"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 12.2.1.4.0",
"product": {
"name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 12.2.1.4.0",
"product_id": "P-12738V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Global Lifecycle Management NextGen OUI Framework"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle HTTP Server Version 12.2.1.4.0",
"product": {
"name": "Oracle HTTP Server Version 12.2.1.4.0",
"product_id": "P-1042V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle HTTP Server"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Identity Manager Version 12.2.1.4.0",
"product": {
"name": "Oracle Identity Manager Version 12.2.1.4.0",
"product_id": "P-1980V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Identity Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle JDeveloper Version 12.2.1.4.0",
"product": {
"name": "Oracle JDeveloper Version 12.2.1.4.0",
"product_id": "P-807V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle JDeveloper"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
"product": {
"name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
"product_id": "P-4647V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Middleware Common Libraries and Tools"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Outside In Technology Version 8.5.7",
"product": {
"name": "Oracle Outside In Technology Version 8.5.7",
"product_id": "P-2276V-8.5.7",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:outside_in_technology:8.5.7:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Outside In Technology"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Reports Developer Version 12.2.1.19.0",
"product": {
"name": "Oracle Reports Developer Version 12.2.1.19.0",
"product_id": "P-159V-12.2.1.19.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Reports Developer Version 12.2.1.4.0",
"product": {
"name": "Oracle Reports Developer Version 12.2.1.4.0",
"product_id": "P-159V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:reports_developer:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Reports Developer"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Service Bus Version 12.2.1.4.0",
"product": {
"name": "Oracle Service Bus Version 12.2.1.4.0",
"product_id": "P-5308V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:service_bus:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Service Bus"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Unified Directory Version 12.2.1.4.0",
"product": {
"name": "Oracle Unified Directory Version 12.2.1.4.0",
"product_id": "P-9118V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Unified Directory"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle WebCenter Content Version 12.2.1.4.0",
"product": {
"name": "Oracle WebCenter Content Version 12.2.1.4.0",
"product_id": "P-2271V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle WebCenter Content"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle WebCenter Portal Version 12.2.1.4.0",
"product": {
"name": "Oracle WebCenter Portal Version 12.2.1.4.0",
"product_id": "P-1696V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle WebCenter Portal"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle WebCenter Sites Version 12.2.1.4.0",
"product": {
"name": "Oracle WebCenter Sites Version 12.2.1.4.0",
"product_id": "P-9617V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle WebCenter Sites"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle WebLogic Server Version 12.2.1.4.0",
"product": {
"name": "Oracle WebLogic Server Version 12.2.1.4.0",
"product_id": "P-5242V-12.2.1.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server Version 14.1.1.0.0",
"product": {
"name": "Oracle WebLogic Server Version 14.1.1.0.0",
"product_id": "P-5242V-14.1.1.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle WebLogic Server"
}
],
"category": "product_family",
"name": "Oracle Fusion Middleware"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Management Pack for Oracle GoldenGate Version 12.2.1.2",
"product": {
"name": "Management Pack for Oracle GoldenGate Version 12.2.1.2",
"product_id": "P-5759V-12.2.1.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:management_pack_for_oracle_goldengate:12.2.1.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Management Pack for Oracle GoldenGate"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle GoldenGate Version 19.1.0.0.0-19.23.0.0.240716",
"product": {
"name": "Oracle GoldenGate Version 19.1.0.0.0-19.23.0.0.240716",
"product_id": "P-5757V-19.1.0.0.0-19.23.0.0.240716",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:goldengate:19.1.0.0.0-19.23.0.0.240716:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle GoldenGate Version 21.3-21.14",
"product": {
"name": "Oracle GoldenGate Version 21.3-21.14",
"product_id": "P-5757V-21.3-21.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:goldengate:21.3-21.14:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle GoldenGate"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle GoldenGate Big Data and Application Adapters Version 19.1.0.0.0-19.1.0.0.18",
"product": {
"name": "Oracle GoldenGate Big Data and Application Adapters Version 19.1.0.0.0-19.1.0.0.18",
"product_id": "P-5760V-19.1.0.0.0-19.1.0.0.18",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:19.1.0.0.0-19.1.0.0.18:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.14.0.0.0",
"product": {
"name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.14.0.0.0",
"product_id": "P-5760V-21.3-21.14.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:21.3-21.14.0.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle GoldenGate Big Data and Application Adapters"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle GoldenGate Studio Version 12.2.0.4.0",
"product": {
"name": "Oracle GoldenGate Studio Version 12.2.0.4.0",
"product_id": "P-10945V-12.2.0.4.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:goldengate_studio:12.2.0.4.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle GoldenGate Studio"
}
],
"category": "product_family",
"name": "Oracle GoldenGate"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Graph Server and Client Version 22.4.7 and prior",
"product": {
"name": "Graph Server and Client Version 22.4.7 and prior",
"product_id": "P-14069V-22.4.7 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graph_server_and_client:22.4.7_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Graph Server and Client Version 23.4.2 and prior",
"product": {
"name": "Graph Server and Client Version 23.4.2 and prior",
"product_id": "P-14069V-23.4.2 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graph_server_and_client:23.4.2_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Graph Server and Client Version 24.1.0 and prior",
"product": {
"name": "Graph Server and Client Version 24.1.0 and prior",
"product_id": "P-14069V-24.1.0 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graph_server_and_client:24.1.0_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Graph Server and Client"
}
],
"category": "product_family",
"name": "Oracle Graph Server and Client"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Healthcare Data Repository Version 8.1.4",
"product": {
"name": "Oracle Healthcare Data Repository Version 8.1.4",
"product_id": "P-9161V-8.1.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:healthcare_data_repository:8.1.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Data Repository Version 8.2.0",
"product": {
"name": "Oracle Healthcare Data Repository Version 8.2.0",
"product_id": "P-9161V-8.2.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:healthcare_data_repository:8.2.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Healthcare Data Repository"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.2.0",
"product": {
"name": "Oracle Healthcare Foundation Version 8.2.0",
"product_id": "P-12950V-8.2.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:healthcare_foundation:8.2.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.2.1",
"product": {
"name": "Oracle Healthcare Foundation Version 8.2.1",
"product_id": "P-12950V-8.2.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:healthcare_foundation:8.2.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.2.2",
"product": {
"name": "Oracle Healthcare Foundation Version 8.2.2",
"product_id": "P-12950V-8.2.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:healthcare_foundation:8.2.2:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.2.3",
"product": {
"name": "Oracle Healthcare Foundation Version 8.2.3",
"product_id": "P-12950V-8.2.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:healthcare_foundation:8.2.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.2.4",
"product": {
"name": "Oracle Healthcare Foundation Version 8.2.4",
"product_id": "P-12950V-8.2.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:healthcare_foundation:8.2.4:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Healthcare Foundation"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Healthcare Master Person Index Version 5.0.0-5.0.9",
"product": {
"name": "Oracle Healthcare Master Person Index Version 5.0.0-5.0.9",
"product_id": "P-8575V-5.0.0-5.0.9",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:healthcare_master_person_index:5.0.0-5.0.9:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Healthcare Master Person Index"
}
],
"category": "product_family",
"name": "Oracle HealthCare Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Hyperion Data Relationship Management Version 11.2.17.0.000",
"product": {
"name": "Oracle Hyperion Data Relationship Management Version 11.2.17.0.000",
"product_id": "P-4375V-11.2.17.0.000",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.17.0.000:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Hyperion Data Relationship Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Hyperion Financial Close Management Version 11.2.17.0.000",
"product": {
"name": "Oracle Hyperion Financial Close Management Version 11.2.17.0.000",
"product_id": "P-5616V-11.2.17.0.000",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:hyperion_financial_close_management:11.2.17.0.000:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Hyperion Financial Close Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Hyperion Infrastructure Technology Version 11.2.17.0.000",
"product": {
"name": "Oracle Hyperion Infrastructure Technology Version 11.2.17.0.000",
"product_id": "P-4392V-11.2.17.0.000",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.17.0.000:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Hyperion Infrastructure Technology"
}
],
"category": "product_family",
"name": "Oracle Hyperion"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Documaker Version 12.6.4",
"product": {
"name": "Oracle Documaker Version 12.6.4",
"product_id": "P-5477V-12.6.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:documaker:12.6.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Documaker Version 12.7.1",
"product": {
"name": "Oracle Documaker Version 12.7.1",
"product_id": "P-5477V-12.7.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:documaker:12.7.1:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Documaker"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Insurance Policy Administration J2EE Version 11.2.11",
"product": {
"name": "Oracle Insurance Policy Administration J2EE Version 11.2.11",
"product_id": "P-5279V-11.2.11",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.2.12:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Insurance Policy Administration J2EE Version 11.3.0-11.3.2",
"product": {
"name": "Oracle Insurance Policy Administration J2EE Version 11.3.0-11.3.2",
"product_id": "P-5279V-11.3.0-11.3.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.3.0-11.3.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Insurance Policy Administration J2EE"
}
],
"category": "product_family",
"name": "Oracle Insurance Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.8.2",
"product": {
"name": "JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.8.2",
"product_id": "P-11681V-Prior to 9.2.8.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:prior_to_9.2.8.2:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.8.3",
"product": {
"name": "JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.8.3",
"product_id": "P-11681V-Prior to 9.2.8.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:prior_to_9.2.8.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "JD Edwards EnterpriseOne Orchestrator"
},
{
"branches": [
{
"category": "product_version_range",
"name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.8.2",
"product": {
"name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.8.2",
"product_id": "P-4781V-Prior to 9.2.8.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:prior_to_9.2.8.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "JD Edwards EnterpriseOne Tools"
},
{
"branches": [
{
"category": "product_version",
"name": "JD Edwards World Security Version A9.4",
"product": {
"name": "JD Edwards World Security Version A9.4",
"product_id": "P-4839V-A9.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "JD Edwards World Security"
}
],
"category": "product_family",
"name": "Oracle JD Edwards"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle GraalVM for JDK Version Oracle GraalVM for JDK:17.0.11",
"product": {
"name": "Oracle GraalVM for JDK Version Oracle GraalVM for JDK:17.0.11",
"product_id": "P-13497V-Oracle GraalVM for JDK:17.0.11",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:17.0.11:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle GraalVM for JDK Version Oracle GraalVM for JDK:21.0.3",
"product": {
"name": "Oracle GraalVM for JDK Version Oracle GraalVM for JDK:21.0.3",
"product_id": "P-13497V-Oracle GraalVM for JDK:21.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:21.0.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle GraalVM for JDK Version Oracle GraalVM for JDK:22.0.1",
"product": {
"name": "Oracle GraalVM for JDK Version Oracle GraalVM for JDK:22.0.1",
"product_id": "P-13497V-Oracle GraalVM for JDK:22.0.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:22.0.1:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle GraalVM for JDK"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.14",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.14",
"product_id": "P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graalvm:20.3.14:*:*:*:enterprise:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.10",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.10",
"product_id": "P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graalvm:21.3.10:*:*:*:enterprise:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM for JDK:17.0.11",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM for JDK:17.0.11",
"product_id": "P-856V-Oracle GraalVM for JDK:17.0.11",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:17.0.11:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM for JDK:21.0.3",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM for JDK:21.0.3",
"product_id": "P-856V-Oracle GraalVM for JDK:21.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:21.0.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM for JDK:22.0.1",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM for JDK:22.0.1",
"product_id": "P-856V-Oracle GraalVM for JDK:22.0.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:22.0.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:11.0.23",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:11.0.23",
"product_id": "P-856V-Oracle Java SE:11.0.23",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:java_se:11.0.23:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:17.0.11",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:17.0.11",
"product_id": "P-856V-Oracle Java SE:17.0.11",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:java_se:17.0.11:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:21.0.3",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:21.0.3",
"product_id": "P-856V-Oracle Java SE:21.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:java_se:21.0.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:22.0.1",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:22.0.1",
"product_id": "P-856V-Oracle Java SE:22.0.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:java_se:22.0.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:8u411",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:8u411",
"product_id": "P-856V-Oracle Java SE:8u411",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:java_se:8u411:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Java SE Version Oracle Java SE:8u411-perf",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:8u411-perf",
"product_id": "P-856V-Oracle Java SE:8u411-perf",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:java_se:8u411:*:*:*:enterprise_performance:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Java SE"
}
],
"category": "product_family",
"name": "Oracle Java SE"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Cluster Version 7.5.34 and prior",
"product": {
"name": "MySQL Cluster Version 7.5.34 and prior",
"product_id": "P-8479V-7.5.34 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_cluster:7.5.34_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 7.6.30 and prior",
"product": {
"name": "MySQL Cluster Version 7.6.30 and prior",
"product_id": "P-8479V-7.6.30 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_cluster:7.6.30_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 8.0.34 and prior",
"product": {
"name": "MySQL Cluster Version 8.0.34 and prior",
"product_id": "P-8479V-8.0.34 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.34_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 8.0.36 and prior",
"product": {
"name": "MySQL Cluster Version 8.0.36 and prior",
"product_id": "P-8479V-8.0.36 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.36_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 8.0.37 and prior",
"product": {
"name": "MySQL Cluster Version 8.0.37 and prior",
"product_id": "P-8479V-8.0.37 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.37_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 8.1.0 and prior",
"product": {
"name": "MySQL Cluster Version 8.1.0 and prior",
"product_id": "P-8479V-8.1.0 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_cluster:8.1.0_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 8.3.0 and prior",
"product": {
"name": "MySQL Cluster Version 8.3.0 and prior",
"product_id": "P-8479V-8.3.0 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_cluster:8.3.0_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 8.4.0 and prior",
"product": {
"name": "MySQL Cluster Version 8.4.0 and prior",
"product_id": "P-8479V-8.4.0 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "MySQL Cluster"
},
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Connectors Version 8.4.0 and prior",
"product": {
"name": "MySQL Connectors Version 8.4.0 and prior",
"product_id": "P-8576V-8.4.0 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_connectors:8.4.0_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "MySQL Connectors"
},
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Enterprise Monitor Version 8.0.38 and prior",
"product": {
"name": "MySQL Enterprise Monitor Version 8.0.38 and prior",
"product_id": "P-8480V-8.0.38 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.38_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "MySQL Enterprise Monitor"
},
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Server Version 8.0.35 and prior",
"product": {
"name": "MySQL Server Version 8.0.35 and prior",
"product_id": "P-8478V-8.0.35 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:8.0.35_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 8.0.36 and prior",
"product": {
"name": "MySQL Server Version 8.0.36 and prior",
"product_id": "P-8478V-8.0.36 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:8.0.36_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 8.0.37 and prior",
"product": {
"name": "MySQL Server Version 8.0.37 and prior",
"product_id": "P-8478V-8.0.37 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:8.0.37_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "MySQL Server Version 8.0.38",
"product": {
"name": "MySQL Server Version 8.0.38",
"product_id": "P-8478V-8.0.38",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:8.0.38:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 8.2.0 and prior",
"product": {
"name": "MySQL Server Version 8.2.0 and prior",
"product_id": "P-8478V-8.2.0 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:8.2.0_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 8.3.0 and prior",
"product": {
"name": "MySQL Server Version 8.3.0 and prior",
"product_id": "P-8478V-8.3.0 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:8.3.0_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 8.4.0 and prior",
"product": {
"name": "MySQL Server Version 8.4.0 and prior",
"product_id": "P-8478V-8.4.0 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "MySQL Server Version 8.4.1",
"product": {
"name": "MySQL Server Version 8.4.1",
"product_id": "P-8478V-8.4.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:8.4.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "MySQL Server Version 9.0.0",
"product": {
"name": "MySQL Server Version 9.0.0",
"product_id": "P-8478V-9.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "MySQL Server"
},
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Workbench Version 8.0.36 and prior",
"product": {
"name": "MySQL Workbench Version 8.0.36 and prior",
"product_id": "P-4627V-8.0.36 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:mysql_workbench:8.0.36_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "MySQL Workbench"
}
],
"category": "product_family",
"name": "Oracle MySQL"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle NoSQL Database Version 1.4",
"product": {
"name": "Oracle NoSQL Database Version 1.4",
"product_id": "P-13373V-1.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:nosql_database:1.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle NoSQL Database Version 1.5",
"product": {
"name": "Oracle NoSQL Database Version 1.5",
"product_id": "P-13373V-1.5",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:nosql_database:1.5:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle NoSQL Database Version Prior to 19.5.42",
"product": {
"name": "Oracle NoSQL Database Version Prior to 19.5.42",
"product_id": "P-13373V-Prior to 19.5.42",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:nosql_database:prior_to_19.5.42:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle NoSQL Database Version Prior to 20.3.40",
"product": {
"name": "Oracle NoSQL Database Version Prior to 20.3.40",
"product_id": "P-13373V-Prior to 20.3.40",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:nosql_database:prior_to_20.3.40:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle NoSQL Database Version Prior to 21.2.27",
"product": {
"name": "Oracle NoSQL Database Version Prior to 21.2.27",
"product_id": "P-13373V-Prior to 21.2.27",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:nosql_database:prior_to_21.2.27:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle NoSQL Database Version Prior to 22.3.46",
"product": {
"name": "Oracle NoSQL Database Version Prior to 22.3.46",
"product_id": "P-13373V-Prior to 22.3.46",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:nosql_database:prior_to_22.3.46:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle NoSQL Database Version Prior to 23.3.32",
"product": {
"name": "Oracle NoSQL Database Version Prior to 23.3.32",
"product_id": "P-13373V-Prior to 23.3.32",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:nosql_database:prior_to_23.3.32:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle NoSQL Database"
}
],
"category": "product_family",
"name": "Oracle NoSQL Database"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
"product": {
"name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
"product_id": "P-5071V-9.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "PeopleSoft Enterprise HCM Human Resources"
},
{
"branches": [
{
"category": "product_version",
"name": "PeopleSoft Enterprise HCM Shared Components Version 9.2",
"product": {
"name": "PeopleSoft Enterprise HCM Shared Components Version 9.2",
"product_id": "P-8943V-9.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_shared_components:9.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "PeopleSoft Enterprise HCM Shared Components"
},
{
"branches": [
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools(OpenSearch) Version 8.59",
"product": {
"name": "PeopleSoft Enterprise PeopleTools(OpenSearch) Version 8.59",
"product_id": "P-5085(OpenSearch)V-8.59",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools(Web Server) Version 8.59",
"product": {
"name": "PeopleSoft Enterprise PeopleTools(Web Server) Version 8.59",
"product_id": "P-5085(Web Server)V-8.59",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools Version 8.59",
"product": {
"name": "PeopleSoft Enterprise PeopleTools Version 8.59",
"product_id": "P-5085V-8.59",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools(OpenSearch) Version 8.60",
"product": {
"name": "PeopleSoft Enterprise PeopleTools(OpenSearch) Version 8.60",
"product_id": "P-5085(OpenSearch)V-8.60",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools(Web Server) Version 8.60",
"product": {
"name": "PeopleSoft Enterprise PeopleTools(Web Server) Version 8.60",
"product_id": "P-5085(Web Server)V-8.60",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools Version 8.60",
"product": {
"name": "PeopleSoft Enterprise PeopleTools Version 8.60",
"product_id": "P-5085V-8.60",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools(OpenSearch) Version 8.61",
"product": {
"name": "PeopleSoft Enterprise PeopleTools(OpenSearch) Version 8.61",
"product_id": "P-5085(OpenSearch)V-8.61",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools(Web Server) Version 8.61",
"product": {
"name": "PeopleSoft Enterprise PeopleTools(Web Server) Version 8.61",
"product_id": "P-5085(Web Server)V-8.61",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools Version 8.61",
"product": {
"name": "PeopleSoft Enterprise PeopleTools Version 8.61",
"product_id": "P-5085V-8.61",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "PeopleSoft Enterprise PeopleTools"
}
],
"category": "product_family",
"name": "Oracle PeopleSoft"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle REST Data Services Version Prior to 23.3.1",
"product": {
"name": "Oracle REST Data Services Version Prior to 23.3.1",
"product_id": "P-9456V-Prior to 23.3.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:rest_data_services:prior_to_23.3.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle REST Data Services Version Prior to 24.1.0",
"product": {
"name": "Oracle REST Data Services Version Prior to 24.1.0",
"product_id": "P-9456V-Prior to 24.1.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:rest_data_services:prior_to_24.1.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle REST Data Services"
}
],
"category": "product_family",
"name": "Oracle REST Data Services"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Assortment Planning Version 15.0.3",
"product": {
"name": "Oracle Retail Assortment Planning Version 15.0.3",
"product_id": "P-1788V-15.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_assortment_planning:15.0.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Assortment Planning Version 16.0.3",
"product": {
"name": "Oracle Retail Assortment Planning Version 16.0.3",
"product_id": "P-1788V-16.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_assortment_planning:16.0.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Retail Assortment Planning"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Financial Integration Version 14.1.3.2",
"product": {
"name": "Oracle Retail Financial Integration Version 14.1.3.2",
"product_id": "P-10722V-14.1.3.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Financial Integration Version 15.0.3.1",
"product": {
"name": "Oracle Retail Financial Integration Version 15.0.3.1",
"product_id": "P-10722V-15.0.3.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_financial_integration:15.0.3.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Financial Integration Version 16.0.3",
"product": {
"name": "Oracle Retail Financial Integration Version 16.0.3",
"product_id": "P-10722V-16.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Financial Integration Version 19.0.1",
"product": {
"name": "Oracle Retail Financial Integration Version 19.0.1",
"product_id": "P-10722V-19.0.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Retail Financial Integration"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Integration Bus Version 14.1.3.2",
"product": {
"name": "Oracle Retail Integration Bus Version 14.1.3.2",
"product_id": "P-1807V-14.1.3.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Integration Bus Version 15.0.3.1",
"product": {
"name": "Oracle Retail Integration Bus Version 15.0.3.1",
"product_id": "P-1807V-15.0.3.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_integration_bus:15.0.3.1:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Integration Bus Version 16.0.3",
"product": {
"name": "Oracle Retail Integration Bus Version 16.0.3",
"product_id": "P-1807V-16.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Integration Bus Version 19.0.1",
"product": {
"name": "Oracle Retail Integration Bus Version 19.0.1",
"product_id": "P-1807V-19.0.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_integration_bus:19.0.1:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Retail Integration Bus"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Predictive Application Server Version 15.0.3",
"product": {
"name": "Oracle Retail Predictive Application Server Version 15.0.3",
"product_id": "P-1823V-15.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Predictive Application Server Version 16.0.3",
"product": {
"name": "Oracle Retail Predictive Application Server Version 16.0.3",
"product_id": "P-1823V-16.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Retail Predictive Application Server"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Version 19.0.5",
"product": {
"name": "Oracle Retail Xstore Office Version 19.0.5",
"product_id": "P-11560V-19.0.5",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_xstore_office:19.0.5:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Version 20.0.3",
"product": {
"name": "Oracle Retail Xstore Office Version 20.0.3",
"product_id": "P-11560V-20.0.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_xstore_office:20.0.3:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Version 20.0.4",
"product": {
"name": "Oracle Retail Xstore Office Version 20.0.4",
"product_id": "P-11560V-20.0.4",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_xstore_office:20.0.4:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Version 22.0.0",
"product": {
"name": "Oracle Retail Xstore Office Version 22.0.0",
"product_id": "P-11560V-22.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_xstore_office:22.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Version 23.0.1",
"product": {
"name": "Oracle Retail Xstore Office Version 23.0.1",
"product_id": "P-11560V-23.0.1",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:retail_xstore_office:23.0.1:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Retail Xstore Office"
}
],
"category": "product_family",
"name": "Oracle Retail Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Siebel CRM Cloud Applications Version 23.11 and prior",
"product": {
"name": "Siebel CRM Cloud Applications Version 23.11 and prior",
"product_id": "P-14107V-23.11 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_cloud_applications:23.11_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Cloud Applications Version 24.1 and prior",
"product": {
"name": "Siebel CRM Cloud Applications Version 24.1 and prior",
"product_id": "P-14107V-24.1 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_cloud_applications:24.1_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Cloud Applications Version 24.3 and prior",
"product": {
"name": "Siebel CRM Cloud Applications Version 24.3 and prior",
"product_id": "P-14107V-24.3 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_cloud_applications:24.3_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Siebel CRM Cloud Applications"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Siebel CRM Deployment Version 22.12 and prior",
"product": {
"name": "Siebel CRM Deployment Version 22.12 and prior",
"product_id": "P-9019V-22.12 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:22.12_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Deployment Version 22.3 and prior",
"product": {
"name": "Siebel CRM Deployment Version 22.3 and prior",
"product_id": "P-9019V-22.3 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:22.3_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Deployment Version 24.2 and prior",
"product": {
"name": "Siebel CRM Deployment Version 24.2 and prior",
"product_id": "P-9019V-24.2 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:24.2_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Deployment Version 24.4 and prior",
"product": {
"name": "Siebel CRM Deployment Version 24.4 and prior",
"product_id": "P-9019V-24.4 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:24.4_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Deployment Version 24.6 and prior",
"product": {
"name": "Siebel CRM Deployment Version 24.6 and prior",
"product_id": "P-9019V-24.6 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:24.6_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Siebel CRM Deployment"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Siebel CRM End User Version 24.2 and prior",
"product": {
"name": "Siebel CRM End User Version 24.2 and prior",
"product_id": "P-9011V-24.2 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_end_user:24.2_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Siebel CRM End User"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Siebel CRM Integration Version 23.12 and prior",
"product": {
"name": "Siebel CRM Integration Version 23.12 and prior",
"product_id": "P-9008V-23.12 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_integration:23.12_and_prior:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Integration Version 24.4 and prior",
"product": {
"name": "Siebel CRM Integration Version 24.4 and prior",
"product_id": "P-9008V-24.4 and prior",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:siebel_crm_integration:24.4_and_prior:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Siebel CRM Integration"
}
],
"category": "product_family",
"name": "Oracle Siebel CRM"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Agile Engineering Data Management Version 6.2.1.0-6.2.1.7",
"product": {
"name": "Oracle Agile Engineering Data Management Version 6.2.1.0-6.2.1.7",
"product_id": "P-4436V-6.2.1.0-6.2.1.7",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0-6.2.1.7:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Agile Engineering Data Management Version 6.2.1.0-6.2.1.9",
"product": {
"name": "Oracle Agile Engineering Data Management Version 6.2.1.0-6.2.1.9",
"product_id": "P-4436V-6.2.1.0-6.2.1.9",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0-6.2.1.9:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Agile Engineering Data Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Autovue for Agile Product Lifecycle Management Version 21.0.2",
"product": {
"name": "Oracle Autovue for Agile Product Lifecycle Management Version 21.0.2",
"product_id": "P-4434V-21.0.2",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_management:21.0.2:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Autovue for Agile Product Lifecycle Management"
}
],
"category": "product_family",
"name": "Oracle Supply Chain"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Solaris Version 11",
"product": {
"name": "Oracle Solaris Version 11",
"product_id": "P-10006V-11",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:solaris:11:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Solaris"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle ZFS Storage Appliance Kit Version 8.8",
"product": {
"name": "Oracle ZFS Storage Appliance Kit Version 8.8",
"product_id": "P-10026V-8.8",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle ZFS Storage Appliance Kit"
}
],
"category": "product_family",
"name": "Oracle Systems"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle TimesTen In-Memory Database Version 22.1.1.1.0-22.1.1.24.0",
"product": {
"name": "Oracle TimesTen In-Memory Database Version 22.1.1.1.0-22.1.1.24.0",
"product_id": "P-1870V-22.1.1.1.0-22.1.1.24.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:22.1.1.1.0-22.1.1.24.0:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle TimesTen In-Memory Database"
}
],
"category": "product_family",
"name": "Oracle TimesTen In-Memory Database"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 24.1.0.0.0",
"product": {
"name": "Oracle Utilities Application Framework Version 24.1.0.0.0",
"product_id": "P-2245V-24.1.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:utilities_application_framework:24.1.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 24.2.0.0.0",
"product": {
"name": "Oracle Utilities Application Framework Version 24.2.0.0.0",
"product_id": "P-2245V-24.2.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:utilities_application_framework:24.2.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
"product_id": "P-2245V-4.3.0.6.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.3.0.6.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
"product_id": "P-2245V-4.4.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
"product_id": "P-2245V-4.4.0.2.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.2.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
"product_id": "P-2245V-4.4.0.3.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.3.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
"product_id": "P-2245V-4.5.0.0.0",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.0.0:*:*:*:*:*:*:*"
}
}
},
{
"category": "product_version_range",
"name": "Oracle Utilities Application Framework Version 4.5.0.1.1-4.5.0.1.3",
"product": {
"name": "Oracle Utilities Application Framework Version 4.5.0.1.1-4.5.0.1.3",
"product_id": "P-2245V-4.5.0.1.1-4.5.0.1.3",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.1-4.5.0.1.3:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle Utilities Application Framework"
}
],
"category": "product_family",
"name": "Oracle Utilities Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle VM VirtualBox Version Prior to 7.0.20",
"product": {
"name": "Oracle VM VirtualBox Version Prior to 7.0.20",
"product_id": "P-8370V-Prior to 7.0.20",
"product_identification_helper": {
"cpe": "cpe:2.3:a:oracle:vm_virtualbox:prior_to_7.0.20:*:*:*:*:*:*:*"
}
}
}
],
"category": "product_name",
"name": "Oracle VM VirtualBox"
}
],
"category": "product_family",
"name": "Oracle Virtualization"
}
],
"category": "vendor",
"name": "Oracle"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2019-10086",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "32369205"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Commons BeanUtils)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications EAGLE Element Management System accessible data as well as unauthorized read access to a subset of Oracle Communications EAGLE Element Management System accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2019-13990",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_present",
"product_ids": [
"P-9633V-11.3.2"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "30623910"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (Quartz)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-9633V-11.3.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-9633V-11.3.2"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
"product_ids": [
"P-9633V-11.3.2"
]
}
]
},
{
"cve": "CVE-2019-17267",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Deployment",
"text": "36346575"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation (jackson-databind)). Supported versions that are affected are 24.4 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9019V-24.4 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9019V-24.4 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9019V-24.4 and prior"
]
}
]
},
{
"cve": "CVE-2020-11987",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "34970649"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Batik)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2020-13956",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
"text": "36339400"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "36545359"
},
{
"system_name": "Oracle Bug ID of Oracle Access Manager",
"text": "36103252"
},
{
"system_name": "Oracle Bug ID of Oracle Business Activity Monitoring",
"text": "36621236"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Third Party (Apache HttpClient)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Platform (Apache HttpClient)). Supported versions that are affected are 7.4.0-7.4.2 and 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Service Catalog and Design accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Enterprise Edition (Apache HttpClient)). Supported versions that are affected are 12.6.4 and 12.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Documaker accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Activity Monitoring product of Oracle Fusion Middleware (component: BAM (Apache HttpClient)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Activity Monitoring. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Activity Monitoring accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1675V-12.2.1.4.0",
"P-2283V-7.4.0-7.4.2",
"P-2283V-8.0.0",
"P-5477V-12.6.4",
"P-5565V-12.2.1.4.0",
"P-5477V-12.7.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1675V-12.2.1.4.0",
"P-5565V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2283V-7.4.0-7.4.2",
"P-2283V-8.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029087.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.6.4",
"P-5477V-12.7.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-1675V-12.2.1.4.0",
"P-2283V-7.4.0-7.4.2",
"P-2283V-8.0.0",
"P-5477V-12.6.4",
"P-5565V-12.2.1.4.0",
"P-5477V-12.7.1"
]
}
]
},
{
"cve": "CVE-2020-1945",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "35884051"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Ant)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2021-23926",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35981623"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI FNDN (Apache XMLBeans)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Ido Hershkovitz"
]
}
],
"cve": "CVE-2021-24112",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "36165696"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net (.NET Core)). Supported versions that are affected are 8.4.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8576V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8576V-8.4.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8576V-8.4.0 and prior"
]
}
]
},
{
"cve": "CVE-2021-27568",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36469040"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (json-smart)). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.0.0.0.0",
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2021-29425",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Service Bus",
"text": "36620930"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "33287687"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Commons IO)). Supported versions that are affected are 46.6.4 and 46.6.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications EAGLE Element Management System accessible data as well as unauthorized read access to a subset of Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Security (Apache Commons IO)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Service Bus accessible data as well as unauthorized read access to a subset of Oracle Service Bus accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-5308V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5308V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5308V-12.2.1.4.0",
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2021-29489",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "36439634"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Highcharts JS)). Supported versions that are affected are 5.5.0-5.5.21 and 6.0.0-6.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029086.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21"
]
}
]
},
{
"cve": "CVE-2021-36090",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Deployment",
"text": "33196307"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation (Apache Commons Compress)). Supported versions that are affected are 22.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9019V-22.3 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9019V-22.3 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9019V-22.3 and prior"
]
}
]
},
{
"cve": "CVE-2021-36373",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "35884051"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Ant)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2021-36374",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "35884051"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Ant)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2021-37533",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
"text": "35346731"
},
{
"system_name": "Oracle Bug ID of Oracle Data Integrator",
"text": "34709074"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
"text": "35006468"
},
{
"system_name": "Oracle Bug ID of Oracle Analytics Desktop",
"text": "36411592"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Content",
"text": "35346791"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "35346719"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service (Apache Commons Net)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Mapviewer (Apache Commons FileUpload)). Supported versions that are affected are Prior to 7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Analytics Desktop. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Analytics Desktop accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server (Apache Commons Net)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Install (Apache Commons Net)). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: JCA Adaptor (Apache Commons Net)). Supported versions that are affected are 12.0.0.4.0-12.0.0.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Commons Net)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2136V-12.0.0.4.0-12.0.0.8.0",
"P-2025V-Prior to 7.8.0",
"P-2196V-12.2.1.4.0",
"P-1370V-13.5.0.0",
"P-2271V-12.2.1.4.0",
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2196V-12.2.1.4.0",
"P-2271V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-Prior to 7.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1370V-13.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027815.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2136V-12.0.0.4.0-12.0.0.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029083.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2136V-12.0.0.4.0-12.0.0.8.0",
"P-2025V-Prior to 7.8.0",
"P-2196V-12.2.1.4.0",
"P-1370V-13.5.0.0",
"P-2271V-12.2.1.4.0",
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2021-41182",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "33798027"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (jQueryUI)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications EAGLE Element Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications EAGLE Element Management System accessible data as well as unauthorized read access to a subset of Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2021-41183",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "33798027"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (jQueryUI)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications EAGLE Element Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications EAGLE Element Management System accessible data as well as unauthorized read access to a subset of Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2021-41184",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "33798027"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (jQueryUI)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications EAGLE Element Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications EAGLE Element Management System accessible data as well as unauthorized read access to a subset of Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2021-44550",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36149530"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Stanford CoreNLP)). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2025V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-0239",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36149530"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Stanford CoreNLP)). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2025V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-1292",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36672559"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (OpenSSL)). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.6.0.0.0",
"P-2025V-7.0.0.0.0",
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.6.0.0.0",
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.6.0.0.0",
"P-2025V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-21797",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36149668"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pipeline Test Failures (Joblib)). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2025V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-22950",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "36336214"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-22965",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "36336214"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-22968",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "36336214"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-22970",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "36336214"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-25987",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_present",
"product_ids": [
"P-5(Oracle Database Core)V-23.4"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36198075"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Database Core (Intel(R) C++ Compiler Classic) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-5(Oracle Database Core)V-23.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-23.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-23.4"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
"product_ids": [
"P-5(Oracle Database Core)V-23.4"
]
}
]
},
{
"cve": "CVE-2022-31160",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "36090006"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC (jQueryUI)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.8.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
}
]
},
{
"cve": "CVE-2022-33879",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Healthcare Foundation",
"text": "35280047"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Foundation product of Oracle HealthCare Applications (component: Upload Services (Apache Tika)). Supported versions that are affected are 8.2.0, 8.2.1, 8.2.2 and 8.2.4. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Healthcare Foundation executes to compromise Oracle Healthcare Foundation. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Healthcare Foundation. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12950V-8.2.4",
"P-12950V-8.2.0",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12950V-8.2.4",
"P-12950V-8.2.0",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031684.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.3,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-12950V-8.2.4",
"P-12950V-8.2.0",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
]
}
]
},
{
"cve": "CVE-2022-34169",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-10945V-12.2.0.4.0"
]
},
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-4379V-21.5.6"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Autovue for Agile Product Lifecycle Management",
"text": "36230153"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "36230244"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "36230267"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "36230234"
},
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "36230274"
},
{
"system_name": "Oracle Bug ID of Siebel CRM Deployment",
"text": "36230416"
},
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
"text": "36230347"
},
{
"system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
"text": "36230325"
},
{
"system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
"text": "36230204"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "36230249"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache Xalan-Java)). Supported versions that are affected are 22.12 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (Apache Xalan-Java)). Supported versions that are affected are 11.2.11 and 11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration J2EE accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: Studio (Apache Xalan-Java)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (Apache Xalan-Java)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Apache Xalan-Java)). Supported versions that are affected are 12.6.4 and 12.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Documaker accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Autovue for Agile Product Lifecycle Management product of Oracle Supply Chain (component: Installation (Apache Xalan-Java)). The supported version that is affected is 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Autovue for Agile Product Lifecycle Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autovue for Agile Product Lifecycle Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core (Apache Xalan-Java)). Supported versions that are affected are 6.2.1.0-6.2.1.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench, Content Acquisition System, Platform Services (Apache Xalan-Java)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Xalan-Java)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Xalan-Java)). Supported versions that are affected are 12.6.1.0.0 and 15.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Policy Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9019V-22.12 and prior",
"P-5279V-11.2.11",
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-4436V-6.2.1.0-6.2.1.7",
"P-9633V-11.3.2",
"P-10900V-15.0.0.0.0",
"P-10900V-12.6.1.0.0",
"P-4434V-21.0.2",
"P-5279V-11.3.0-11.3.2",
"P-5477V-12.6.4",
"P-5477V-12.7.1"
],
"known_not_affected": [
"P-10945V-12.2.0.4.0",
"P-4379V-21.5.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9019V-22.12 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5279V-11.2.11",
"P-5279V-11.3.0-11.3.2",
"P-5477V-12.6.4",
"P-5477V-12.7.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10945V-12.2.0.4.0",
"P-4379V-21.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4434V-21.0.2",
"P-4436V-6.2.1.0-6.2.1.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032936.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-15.0.0.0.0",
"P-10900V-12.6.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033770.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9019V-22.12 and prior",
"P-9633V-11.3.2",
"P-10900V-15.0.0.0.0",
"P-10900V-12.6.1.0.0",
"P-5279V-11.2.11",
"P-11125V-46.6.4",
"P-4434V-21.0.2",
"P-11125V-46.6.5",
"P-5279V-11.3.0-11.3.2",
"P-5477V-12.6.4",
"P-4436V-6.2.1.0-6.2.1.7",
"P-5477V-12.7.1"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-10945V-12.2.0.4.0",
"P-4379V-21.5.6"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-10945V-12.2.0.4.0"
]
},
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-4379V-21.5.6"
]
}
]
},
{
"cve": "CVE-2022-34381",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
"text": "36299611"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Platform (BSAFE Crypto-J)). Supported versions that are affected are 12.0.0.4.0-12.0.0.8.0 and 15.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2136V-12.0.0.4.0-12.0.0.8.0",
"P-2136V-15.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2136V-12.0.0.4.0-12.0.0.8.0",
"P-2136V-15.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029083.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2136V-12.0.0.4.0-12.0.0.8.0",
"P-2136V-15.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-36033",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "34897694"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (jsoup)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications EAGLE Element Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications EAGLE Element Management System accessible data as well as unauthorized read access to a subset of Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2022-36944",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "35767128"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Scala)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
}
]
},
{
"cve": "CVE-2022-37434",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_present",
"product_ids": [
"P-5(Oracle Database Core)V-21.11-21.14",
"P-5(Oracle Database Core)V-19.20-19.23"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36103892"
},
{
"system_name": "Oracle Bug ID of Siebel CRM Deployment",
"text": "34892084"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Database Core (Zlib) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Repository Utilities (zlib)). Supported versions that are affected are 24.6 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9019V-24.6 and prior"
],
"known_not_affected": [
"P-5(Oracle Database Core)V-19.20-19.23",
"P-5(Oracle Database Core)V-21.11-21.14"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-21.11-21.14",
"P-5(Oracle Database Core)V-19.20-19.23"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9019V-24.6 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-21.11-21.14",
"P-5(Oracle Database Core)V-19.20-19.23"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9019V-24.6 and prior"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
"product_ids": [
"P-5(Oracle Database Core)V-21.11-21.14",
"P-5(Oracle Database Core)V-19.20-19.23"
]
}
]
},
{
"cve": "CVE-2022-3786",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Deployment",
"text": "36213692"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (OpenSSL)). Supported versions that are affected are 24.2 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9019V-24.2 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9019V-24.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-9019V-24.2 and prior"
]
}
]
},
{
"cve": "CVE-2022-38398",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "34970649"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Batik)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2022-38648",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "34970649"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Batik)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2022-40146",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "34970649"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Batik)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2022-40149",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35033964"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-40150",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35033964"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-40152",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36146623"
},
{
"system_name": "Oracle Bug ID of Oracle JDeveloper",
"text": "36363766"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Woodstox)). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper (Woodstox)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.0.0.0.0",
"P-807V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-807V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-7.0.0.0.0",
"P-807V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-41704",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "34970649"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Batik)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2022-41881",
"ids": [
{
"system_name": "Oracle Bug ID of Fleet Patching and Provisioning (Netty)",
"text": "34945160"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Fleet Patching and Provisioning (Netty) component of Oracle Database Server. The supported version that is affected is 23.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and Provisioning (Netty). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fleet Patching and Provisioning (Netty). CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14599V-23.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14599V-23.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14599V-23.4"
]
}
]
},
{
"cve": "CVE-2022-41915",
"ids": [
{
"system_name": "Oracle Bug ID of Fleet Patching and Provisioning (Netty)",
"text": "34945160"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Fleet Patching and Provisioning (Netty) component of Oracle Database Server. The supported version that is affected is 23.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and Provisioning (Netty). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fleet Patching and Provisioning (Netty). CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14599V-23.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14599V-23.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14599V-23.4"
]
}
]
},
{
"cve": "CVE-2022-42003",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Deployment",
"text": "36346575"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation (jackson-databind)). Supported versions that are affected are 24.4 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9019V-24.4 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9019V-24.4 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9019V-24.4 and prior"
]
}
]
},
{
"cve": "CVE-2022-42890",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "34970649"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Batik)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
]
}
]
},
{
"cve": "CVE-2022-45378",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "36474828"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portal Core (Apache SOAP)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1696V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1696V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-1696V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-45685",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35033964"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-45693",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35033964"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-46337",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-10945V-12.2.0.4.0"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
"text": "36131978"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: Studio (Apache Derby)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-10945V-12.2.0.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10945V-12.2.0.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-10945V-12.2.0.4.0"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-10945V-12.2.0.4.0"
]
}
]
},
{
"cve": "CVE-2022-48174",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
"text": "36755450"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: OSO (BusyBox)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033771.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
]
}
]
},
{
"cve": "CVE-2023-1370",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36469040"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
"text": "35408099"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (json-smart)). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Install (json-smart)). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.0.0.0.0",
"P-2025V-12.2.1.4.0",
"P-1370V-13.5.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1370V-13.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027815.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-1370V-13.5.0.0",
"P-2025V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-1436",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36434063"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35033964"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security (Jettison)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025(Analytics Server)V-12.2.1.4.0",
"P-2025(BI Platform Security)V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025(BI Platform Security)V-12.2.1.4.0",
"P-2025(Analytics Server)V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025(BI Platform Security)V-12.2.1.4.0",
"P-2025(Analytics Server)V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-20861",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "36336214"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-21036",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
"text": "35660122"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (aCropalypse)). Supported versions that are affected are 11.2.11 and 11.3.0-11.3.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Insurance Policy Administration J2EE executes to compromise Oracle Insurance Policy Administration J2EE. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Insurance Policy Administration J2EE accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5279V-11.3.0-11.3.2",
"P-5279V-11.2.11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5279V-11.2.11",
"P-5279V-11.3.0-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5279V-11.2.11",
"P-5279V-11.3.0-11.3.2"
]
}
]
},
{
"cve": "CVE-2023-22081",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Deployment",
"text": "36404715"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation (Oracle Java SE)). Supported versions that are affected are 24.6 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9019V-24.6 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9019V-24.6 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-9019V-24.6 and prior"
]
}
]
},
{
"cve": "CVE-2023-24998",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "35170824"
},
{
"system_name": "Oracle Bug ID of Oracle Service Bus",
"text": "36589793"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "35170838"
},
{
"system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
"text": "35170806"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: File Upload (Apache Commons FileUpload)). Supported versions that are affected are 6.2.1.0-6.2.1.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (Apache Commons FileUpload)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Commons FileUpload)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Commons FileUpload)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Service Bus. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-9633V-11.3.2",
"P-11125V-46.6.5",
"P-5308V-12.2.1.4.0",
"P-4436V-6.2.1.0-6.2.1.9"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4436V-6.2.1.0-6.2.1.9"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032936.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5308V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9633V-11.3.2",
"P-5308V-12.2.1.4.0",
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-4436V-6.2.1.0-6.2.1.9"
]
}
]
},
{
"cve": "CVE-2023-26031",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Analytics Desktop",
"text": "36277018"
},
{
"system_name": "Oracle Bug ID of Oracle NoSQL Database",
"text": "36083387"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36083379"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle NoSQL Database (component: Administration (Apache Hadoop)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Hadoop)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Analytics Server (Apache Hadoop)). Supported versions that are affected are Prior to 7.7.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Analytics Desktop. Successful attacks of this vulnerability can result in takeover of Oracle Analytics Desktop. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-Prior to 7.7.0",
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"known_not_affected": [
"P-13373V-1.4",
"P-13373V-1.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-Prior to 7.7.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13373V-1.4",
"P-13373V-1.5"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2025V-Prior to 7.7.0",
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5"
]
}
]
},
{
"cve": "CVE-2023-28755",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35435937"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleSoft CDA (Ruby)). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.61",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2023-28756",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35435937"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleSoft CDA (Ruby)). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.61",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2023-29081",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebCenter Content",
"text": "36303652"
},
{
"system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
"text": "36303570"
},
{
"system_name": "Oracle Bug ID of Oracle Hyperion Financial Close Management",
"text": "36303617"
},
{
"system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
"text": "36303615"
},
{
"system_name": "Oracle Bug ID of Oracle Communications ASAP",
"text": "36303557"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "36303566"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (InstallShield)). The supported version that is affected is 11.2.17.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Installation and Configuration (InstallShield)). The supported version that is affected is 11.2.17.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Transall (InstallShield)). The supported version that is affected is 12.7.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Documaker executes to compromise Oracle Documaker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Documaker. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications ASAP product of Oracle Communications Applications (component: Installation (InstallShield)). The supported version that is affected is 7.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications ASAP executes to compromise Oracle Communications ASAP. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications ASAP. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager (InstallShield)). The supported version that is affected is 11.2.17.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Close Management executes to compromise Oracle Hyperion Financial Close Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Close Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Integration Suite (InstallShield)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2271V-12.2.1.4.0",
"P-4375V-11.2.17.0.000",
"P-5616V-11.2.17.0.000",
"P-2260V-7.4",
"P-4392V-11.2.17.0.000",
"P-5477V-12.7.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4375V-11.2.17.0.000",
"P-5616V-11.2.17.0.000",
"P-4392V-11.2.17.0.000"
],
"url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2260V-7.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029082.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2271V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2271V-12.2.1.4.0",
"P-4375V-11.2.17.0.000",
"P-5616V-11.2.17.0.000",
"P-2260V-7.4",
"P-4392V-11.2.17.0.000",
"P-5477V-12.7.1"
]
}
]
},
{
"cve": "CVE-2023-2975",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36278320"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Liquidity Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management as well as unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.7.0.0.0",
"P-13304V-14.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-2976",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Healthcare Foundation",
"text": "35770260"
},
{
"system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
"text": "35561936"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Sites",
"text": "35770223"
},
{
"system_name": "Oracle Bug ID of Oracle Fusion Middleware",
"text": "36726388"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Google Guava)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Global Lifecycle Management NextGen OUI Framework executes to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle Management NextGen OUI Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Global Lifecycle Management NextGen OUI Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Google Guava)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Sites executes to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Foundation product of Oracle HealthCare Applications (component: Core (Google Guava)). Supported versions that are affected are 8.2.0, 8.2.1, 8.2.2 and 8.2.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Healthcare Foundation executes to compromise Oracle Healthcare Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle Healthcare Foundation accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Fusion Middleware (component: Oracle Database Client for Fusion Middleware (Google Guava)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Fusion Middleware executes to compromise Oracle Fusion Middleware. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Fusion Middleware accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9617V-12.2.1.4.0",
"P-12738V-12.2.1.4.0",
"P-1032V-12.2.1.4.0",
"P-12950V-8.2.3",
"P-12950V-8.2.0",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9617V-12.2.1.4.0",
"P-12738V-12.2.1.4.0",
"P-1032V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12950V-8.2.3",
"P-12950V-8.2.0",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031684.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9617V-12.2.1.4.0",
"P-12738V-12.2.1.4.0",
"P-12950V-8.2.3",
"P-12950V-8.2.0",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
]
},
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1032V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-33201",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "35761808"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "35761768"
},
{
"system_name": "Oracle Bug ID of Siebel CRM Integration",
"text": "35825351"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (Bouncy Castle Java Library)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: AI (Bouncy Castle Java Library)). Supported versions that are affected are 24.4 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Bouncy Castle Java Library)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-11681V-Prior to 9.2.8.2",
"P-9008V-24.4 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9008V-24.4 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.8.2",
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-9008V-24.4 and prior"
]
}
]
},
{
"cve": "CVE-2023-33202",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Analytics Desktop",
"text": "36503576"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Analytics Server (Bouncy Castle Java Library)). Supported versions that are affected are Prior to 7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Analytics Desktop executes to compromise Oracle Analytics Desktop. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Analytics Desktop. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-Prior to 7.8.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-Prior to 7.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-Prior to 7.8.0"
]
}
]
},
{
"cve": "CVE-2023-34034",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebCenter Sites",
"text": "35677957"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Spring Security)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9617V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9617V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9617V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-34040",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "inline_mitigations_already_exist",
"product_ids": [
"P-14117V-23.4.0"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "35786388"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-14117V-23.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14117V-23.4.0"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
"product_ids": [
"P-14117V-23.4.0"
]
}
]
},
{
"cve": "CVE-2023-34055",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36101551"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Spring Boot)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
}
]
},
{
"cve": "CVE-2023-3446",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "35702873"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36278320"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Liquidity Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management as well as unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-4781V-Prior to 9.2.8.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-35116",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
"text": "36474817"
},
{
"system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
"text": "35561936"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Google Guava)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Global Lifecycle Management NextGen OUI Framework executes to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle Management NextGen OUI Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Global Lifecycle Management NextGen OUI Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: REST Services Manager (jackson-databind)). Supported versions that are affected are 12.0.0.4.0-12.0.0.8.0 and 15.0.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9437V-12.0.0.4.0-12.0.0.8.0",
"P-12738V-12.2.1.4.0",
"P-9437V-15.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12738V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9437V-15.0.0.0.0",
"P-9437V-12.0.0.4.0-12.0.0.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033654.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-12738V-12.2.1.4.0"
]
},
{
"cvss_v3": {
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9437V-15.0.0.0.0",
"P-9437V-12.0.0.4.0-12.0.0.8.0"
]
}
]
},
{
"cve": "CVE-2023-35887",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "35880689"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC (Apache Mina SSHD)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.8.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
}
]
},
{
"cve": "CVE-2023-36478",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Unified Directory",
"text": "35902509"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: Containers (Eclipse Jetty)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9118V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9118V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9118V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-36479",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Unified Directory",
"text": "35902509"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
"text": "35880629"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Eclipse Jetty)). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: Containers (Eclipse Jetty)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9118V-12.2.1.4.0",
"P-1370V-13.5.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1370V-13.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027815.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9118V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-1370V-13.5.0.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9118V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-37536",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Autovue for Agile Product Lifecycle Management",
"text": "35955432"
},
{
"system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
"text": "35955443"
},
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35955464"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Autovue for Agile Product Lifecycle Management product of Oracle Supply Chain (component: Installation (Apache Xerces-C++)). The supported version that is affected is 21.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autovue for Agile Product Lifecycle Management. Successful attacks of this vulnerability can result in takeover of Oracle Autovue for Agile Product Lifecycle Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Essbase Web Platform (Apache Xerces-C++)). The supported version that is affected is 21.5.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Essbase executes to compromise Oracle Essbase. Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core (Apache Xerces-C++)). Supported versions that are affected are 6.2.1.0-6.2.1.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4434V-21.0.2",
"P-4436V-6.2.1.0-6.2.1.9",
"P-4379V-21.5.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4434V-21.0.2",
"P-4436V-6.2.1.0-6.2.1.9"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032936.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4434V-21.0.2",
"P-4436V-6.2.1.0-6.2.1.9"
]
},
{
"cvss_v3": {
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4379V-21.5.6"
]
}
]
},
{
"cve": "CVE-2023-37920",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
"text": "36618070"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36618029"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36618059"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36618057"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36618053"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36618060"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36618061"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (Certifi)). Supported versions that are affected are 8.0.34 and prior and 8.1.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Certifi)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Certifi)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Certifi)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Certifi)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (Certifi)). Supported versions that are affected are 5.1 and 5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Certifi)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10761V-5.1",
"P-14118V-23.4.2",
"P-14277V-23.4.0-23.4.4",
"P-14117V-23.4.0",
"P-14121V-23.4.0-23.4.3",
"P-10761V-5.2",
"P-14117V-24.1.0",
"P-8479V-8.0.34 and prior",
"P-8479V-8.1.0 and prior",
"P-14123V-23.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.0.34 and prior",
"P-8479V-8.1.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10761V-5.1",
"P-10761V-5.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033757.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.0",
"P-14117V-24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10761V-5.1",
"P-14118V-23.4.2",
"P-14277V-23.4.0-23.4.4",
"P-14117V-23.4.0",
"P-14121V-23.4.0-23.4.3",
"P-10761V-5.2",
"P-14117V-24.1.0",
"P-8479V-8.0.34 and prior",
"P-8479V-8.1.0 and prior",
"P-14123V-23.4.0"
]
}
]
},
{
"cve": "CVE-2023-3817",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36278320"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "35702873"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Liquidity Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management as well as unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-4781V-Prior to 9.2.8.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
}
]
},
{
"cve": "CVE-2023-38552",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "36010587"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.8.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
}
]
},
{
"cve": "CVE-2023-38709",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "36736528"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
"text": "36736524"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (Apache HTTP Server)). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache HTTP Server)). Supported versions that are affected are 5.5.0-5.5.21 and 6.0.0-6.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.21",
"P-14597V-6.0.0-6.0.4",
"P-14489V-24.2.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14489V-24.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033759.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029086.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21",
"P-14489V-24.2.0"
]
}
]
},
{
"cve": "CVE-2023-39331",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "36010587"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.8.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
}
]
},
{
"cve": "CVE-2023-39332",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "36010587"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.8.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
}
]
},
{
"cve": "CVE-2023-40167",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Unified Directory",
"text": "35902509"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
"text": "35880629"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Eclipse Jetty)). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: Containers (Eclipse Jetty)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9118V-12.2.1.4.0",
"P-1370V-13.5.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1370V-13.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027815.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9118V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-1370V-13.5.0.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9118V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-4043",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle REST Data Services",
"text": "36505041"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle REST Data Services (component: ORDS (Eclipse Parsson)). Supported versions that are affected are Prior to 23.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9456V-Prior to 23.3.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9456V-Prior to 23.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-9456V-Prior to 23.3.1"
]
}
]
},
{
"cve": "CVE-2023-40743",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-2283V-7.4.0-7.4.2",
"P-2283V-8.0.0"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
"text": "36339386"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Platform (Apache Axis)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-2283V-7.4.0-7.4.2",
"P-2283V-8.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2283V-7.4.0-7.4.2",
"P-2283V-8.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029087.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2283V-7.4.0-7.4.2",
"P-2283V-8.0.0"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-2283V-7.4.0-7.4.2",
"P-2283V-8.0.0"
]
}
]
},
{
"cve": "CVE-2023-41105",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
"text": "36217283"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Python)). Supported versions that are affected are 23.11 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14107V-23.11 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14107V-23.11 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-14107V-23.11 and prior"
]
}
]
},
{
"cve": "CVE-2023-41900",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Unified Directory",
"text": "35902509"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
"text": "35880629"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Eclipse Jetty)). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: Containers (Eclipse Jetty)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9118V-12.2.1.4.0",
"P-1370V-13.5.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1370V-13.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027815.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9118V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-1370V-13.5.0.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9118V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-42503",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35844251"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Webserver (Apache Commons Compress)). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.61",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2023-44483",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "35977841"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Santuario XML Security For Java)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
}
]
},
{
"cve": "CVE-2023-44487",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-13373V-Prior to 19.5.42",
"P-13373V-Prior to 20.3.40",
"P-13373V-Prior to 23.3.32",
"P-13373V-Prior to 22.3.46",
"P-13373V-Prior to 21.2.27"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Autovue for Agile Product Lifecycle Management",
"text": "35998955"
},
{
"system_name": "Oracle Bug ID of Oracle NoSQL Database",
"text": "35999543"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "36010587"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
"text": "36060114"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence",
"text": "36060121"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
"text": "36060123"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Autovue for Agile Product Lifecycle Management product of Oracle Supply Chain (component: Core (Eclipse Jetty)). The supported version that is affected is 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Autovue for Agile Product Lifecycle Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autovue for Agile Product Lifecycle Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle NoSQL Database (component: Administration (Netty)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (Nghttp2)). Supported versions that are affected are 2.0.0.0.0 and 2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Performance Intelligence product of Oracle Communications (component: Management (Nghttp2)). Supported versions that are affected are 10.4.0.4.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Performance Intelligence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Performance Intelligence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (Nghttp2)). Supported versions that are affected are 4.1.0, 4.2.0, 9.2.0 and 9.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Session Border Controller. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11044V-10.4.0.4.3 and prior",
"P-10750V-4.1.0",
"P-10750V-4.2.0",
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0",
"P-4434V-21.0.2",
"P-10750V-9.2.0",
"P-10750V-9.3.0",
"P-4781V-Prior to 9.2.8.2"
],
"known_not_affected": [
"P-13373V-Prior to 19.5.42",
"P-13373V-Prior to 20.3.40",
"P-13373V-Prior to 23.3.32",
"P-13373V-Prior to 22.3.46",
"P-13373V-Prior to 21.2.27"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4434V-21.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032936.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13373V-Prior to 19.5.42",
"P-13373V-Prior to 20.3.40",
"P-13373V-Prior to 23.3.32",
"P-13373V-Prior to 22.3.46",
"P-13373V-Prior to 21.2.27"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11044V-10.4.0.4.3 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033769.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10750V-4.1.0",
"P-10750V-4.2.0",
"P-10750V-9.2.0",
"P-10750V-9.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032665.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11044V-10.4.0.4.3 and prior",
"P-10750V-4.1.0",
"P-10750V-4.2.0",
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0",
"P-4434V-21.0.2",
"P-10750V-9.2.0",
"P-10750V-9.3.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13373V-Prior to 19.5.42",
"P-13373V-Prior to 20.3.40",
"P-13373V-Prior to 23.3.32",
"P-13373V-Prior to 22.3.46",
"P-13373V-Prior to 21.2.27"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-13373V-Prior to 19.5.42",
"P-13373V-Prior to 20.3.40",
"P-13373V-Prior to 23.3.32",
"P-13373V-Prior to 22.3.46",
"P-13373V-Prior to 21.2.27"
]
}
]
},
{
"cve": "CVE-2023-45853",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_present",
"product_ids": [
"P-5(Oracle Database Core)V-21.11-21.14",
"P-5(Oracle Database Core)V-19.20-19.23"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36103892"
},
{
"system_name": "Oracle Bug ID of Oracle Outside In Technology",
"text": "36013125"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36565772"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters (zlib)). The supported version that is affected is 8.5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Database Core (Zlib) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (zlib)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1042V-12.2.1.4.0",
"P-2276V-8.5.7"
],
"known_not_affected": [
"P-5(Oracle Database Core)V-19.20-19.23",
"P-5(Oracle Database Core)V-21.11-21.14"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0",
"P-2276V-8.5.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-21.11-21.14",
"P-5(Oracle Database Core)V-19.20-19.23"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-1042V-12.2.1.4.0",
"P-2276V-8.5.7"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-21.11-21.14",
"P-5(Oracle Database Core)V-19.20-19.23"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
"product_ids": [
"P-5(Oracle Database Core)V-21.11-21.14",
"P-5(Oracle Database Core)V-19.20-19.23"
]
}
]
},
{
"cve": "CVE-2023-46218",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
"text": "36127644"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (curl)). Supported versions that are affected are 2.0.0.0.0 and 2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Converged Charging System accessible data as well as unauthorized read access to a subset of Oracle Communications Converged Charging System accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14565V-2.0.0.1.0",
"P-14565V-2.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
]
}
]
},
{
"cve": "CVE-2023-46219",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
"text": "36127644"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (curl)). Supported versions that are affected are 2.0.0.0.0 and 2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Converged Charging System accessible data as well as unauthorized read access to a subset of Oracle Communications Converged Charging System accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14565V-2.0.0.1.0",
"P-14565V-2.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
]
}
]
},
{
"cve": "CVE-2023-46589",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
"text": "36110055"
},
{
"system_name": "Oracle Bug ID of Siebel CRM End User",
"text": "36110111"
},
{
"system_name": "Oracle Bug ID of Oracle Analytics Desktop",
"text": "36396300"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36148988"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: EAI, UI (Apache Tomcat)). Supported versions that are affected are 24.2 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Tomcat)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Installation (Apache Tomcat)). Supported versions that are affected are 6.2.1.0-6.2.1.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Analytics Visualization (Apache Tomcat)). Supported versions that are affected are Prior to 7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Analytics Desktop. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Analytics Desktop accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-23.4.0-23.4.4",
"P-2025V-Prior to 7.8.0",
"P-9011V-24.2 and prior",
"P-4436V-6.2.1.0-6.2.1.9"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9011V-24.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4436V-6.2.1.0-6.2.1.9"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032936.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-Prior to 7.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-14277V-23.4.0-23.4.4",
"P-2025V-Prior to 7.8.0",
"P-9011V-24.2 and prior",
"P-4436V-6.2.1.0-6.2.1.9"
]
}
]
},
{
"cve": "CVE-2023-46750",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebCenter Sites",
"text": "36190252"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Apache Shiro)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data as well as unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9617V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9617V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-9617V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-47248",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36509304"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (PyArrow)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
}
]
},
{
"cve": "CVE-2023-4759",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
"text": "36296534"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Eclipse JGit)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12738V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12738V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-12738V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-47627",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
"text": "36173923"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)). Supported versions that are affected are 24.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14107V-24.1 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14107V-24.1 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-14107V-24.1 and prior"
]
}
]
},
{
"cve": "CVE-2023-48795",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Data Integrator",
"text": "36223777"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
"text": "36135641"
},
{
"system_name": "Oracle Bug ID of Oracle Application Testing Suite",
"text": "36223773"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36135621"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "36223871"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
"text": "36223782"
},
{
"system_name": "Oracle Bug ID of Oracle Analytics Desktop",
"text": "36396301"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
"text": "36223826"
},
{
"system_name": "Oracle Bug ID of Oracle GoldenGate",
"text": "36223837"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36135626"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36223803"
},
{
"system_name": "Oracle Bug ID of Oracle NoSQL Database",
"text": "36223847"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (libssh)). Supported versions that are affected are 2.0.0.0.0 and 2.0.0.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Converged Charging System accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Install (Apache Mina SSHD)). The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Runtime Java agent for ODI (Apache Mina SSHD)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Apache Mina SSHD)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Enterprise Data Quality. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Data Quality accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Apache Mina SSHD)). Supported versions that are affected are 23.4.0-23.4.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Apache Mina SSHD)). The supported version that is affected is 13.5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle GoldenGate (component: General (Apache Mina SSHD)). Supported versions that are affected are 19.1.0.0.0-19.23.0.0.240716 and 21.3-21.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle NoSQL Database (component: Administration (Apache Mina SSHD)). Supported versions that are affected are Prior to 19.5.42, Prior to 20.3.40, Prior to 21.2.27, Prior to 22.3.46 and Prior to 23.3.32. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle NoSQL Database. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle NoSQL Database accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Server (Apache Mina SSHD)). Supported versions that are affected are 8.60 and 8.61. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Analytics Visualization (Apache Mina SSHD)). Supported versions that are affected are Prior to 7.8.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Analytics Desktop. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Analytics Desktop accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (libssh)). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Cluster accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)). Supported versions that are affected are 8.0.36 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4622V-13.3.0.1",
"P-8479V-8.4.0 and prior",
"P-5757V-21.3-21.14",
"P-14121V-23.4.0-23.4.3",
"P-4627V-8.0.36 and prior",
"P-14565V-2.0.0.1.0",
"P-2025V-Prior to 7.8.0",
"P-13373V-Prior to 19.5.42",
"P-13373V-Prior to 20.3.40",
"P-5757V-19.1.0.0.0-19.23.0.0.240716",
"P-13373V-Prior to 23.3.32",
"P-8479V-8.0.37 and prior",
"P-14565V-2.0.0.0.0",
"P-2196V-12.2.1.4.0",
"P-13373V-Prior to 22.3.46",
"P-1370V-13.5.0.0",
"P-13373V-Prior to 21.2.27",
"P-9464V-12.2.1.4.0",
"P-5085V-8.61",
"P-5085V-8.60"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4622V-13.3.0.1",
"P-1370V-13.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027815.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2196V-12.2.1.4.0",
"P-9464V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5757V-21.3-21.14",
"P-13373V-Prior to 19.5.42",
"P-13373V-Prior to 20.3.40",
"P-5757V-19.1.0.0.0-19.23.0.0.240716",
"P-13373V-Prior to 23.3.32",
"P-13373V-Prior to 22.3.46",
"P-13373V-Prior to 21.2.27"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.61",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-Prior to 7.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.4.0 and prior",
"P-8479V-8.0.37 and prior",
"P-4627V-8.0.36 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4622V-13.3.0.1",
"P-8479V-8.4.0 and prior",
"P-5757V-21.3-21.14",
"P-14121V-23.4.0-23.4.3",
"P-4627V-8.0.36 and prior",
"P-14565V-2.0.0.1.0",
"P-2025V-Prior to 7.8.0",
"P-13373V-Prior to 19.5.42",
"P-13373V-Prior to 20.3.40",
"P-5757V-19.1.0.0.0-19.23.0.0.240716",
"P-13373V-Prior to 23.3.32",
"P-8479V-8.0.37 and prior",
"P-14565V-2.0.0.0.0",
"P-2196V-12.2.1.4.0",
"P-13373V-Prior to 22.3.46",
"P-1370V-13.5.0.0",
"P-13373V-Prior to 21.2.27",
"P-9464V-12.2.1.4.0",
"P-5085V-8.61",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2023-49081",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
"text": "36173923"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)). Supported versions that are affected are 24.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14107V-24.1 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14107V-24.1 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-14107V-24.1 and prior"
]
}
]
},
{
"cve": "CVE-2023-49082",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
"text": "36173923"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)). Supported versions that are affected are 24.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14107V-24.1 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14107V-24.1 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-14107V-24.1 and prior"
]
}
]
},
{
"cve": "CVE-2023-49083",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36146809"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pipeline Test Failures (Cryptography)). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-50447",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "36253431"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Credit Facilities Process Management",
"text": "36253432"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Origination",
"text": "36253436"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Branch",
"text": "36253428"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Cash Management",
"text": "36253429"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Basic Config/Maintenances (Pillow)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks of this vulnerability can result in takeover of Oracle Banking Origination. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Pillow)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Pillow)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management. Successful attacks of this vulnerability can result in takeover of Oracle Banking Cash Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Credit Facilities Process Management product of Oracle Financial Services Applications (component: Common (Pillow)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Credit Facilities Process Management. Successful attacks of this vulnerability can result in takeover of Oracle Banking Credit Facilities Process Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Pillow)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14324V-14.5.0.0.0",
"P-14195V-14.4.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-14195V-14.6.0.0.0",
"P-14195V-14.5.0.0.0",
"P-14324V-14.4.0.0.0",
"P-13701V-14.4.0.0.0",
"P-14195V-14.7.0.0.0",
"P-13701V-14.5.0.0.0",
"P-14325V-14.7.0.0.0",
"P-14324V-14.7.0.0.0",
"P-13701V-14.6.0.0.0",
"P-14325V-14.6.0.0.0",
"P-13703V-14.5.0.0.0",
"P-13703V-14.6.0.0.0",
"P-13701V-14.7.0.0.0",
"P-14324V-14.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14324V-14.5.0.0.0",
"P-14195V-14.4.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-14195V-14.6.0.0.0",
"P-14195V-14.5.0.0.0",
"P-14324V-14.4.0.0.0",
"P-13701V-14.4.0.0.0",
"P-14195V-14.7.0.0.0",
"P-13701V-14.5.0.0.0",
"P-14325V-14.7.0.0.0",
"P-14324V-14.7.0.0.0",
"P-13701V-14.6.0.0.0",
"P-14325V-14.6.0.0.0",
"P-13703V-14.5.0.0.0",
"P-13703V-14.6.0.0.0",
"P-13701V-14.7.0.0.0",
"P-14324V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14324V-14.5.0.0.0",
"P-14195V-14.4.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-14195V-14.6.0.0.0",
"P-14195V-14.5.0.0.0",
"P-14324V-14.4.0.0.0",
"P-13701V-14.4.0.0.0",
"P-14195V-14.7.0.0.0",
"P-13701V-14.5.0.0.0",
"P-14325V-14.7.0.0.0",
"P-14324V-14.7.0.0.0",
"P-13701V-14.6.0.0.0",
"P-14325V-14.6.0.0.0",
"P-13703V-14.5.0.0.0",
"P-13703V-14.6.0.0.0",
"P-13701V-14.7.0.0.0",
"P-14324V-14.6.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-5072",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Integration",
"text": "35915567"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "36420297"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (JSON-java)). Supported versions that are affected are 23.12 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Discussion Forums (JSON-java)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9008V-23.12 and prior",
"P-1696V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9008V-23.12 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1696V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-1696V-12.2.1.4.0",
"P-9008V-23.12 and prior"
]
}
]
},
{
"cve": "CVE-2023-51074",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "36308622"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (JsonPath)). Supported versions that are affected are 8.0.7, 8.0.8, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-5680V-8.0.7",
"P-5680V-8.0.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-5680V-8.0.7",
"P-5680V-8.0.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031528.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-5680V-8.0.7",
"P-5680V-8.0.8"
]
}
]
},
{
"cve": "CVE-2023-51775",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-14250V-23.4.0"
]
},
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_present",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36675067"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36675072"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36675076"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "36743604"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36384569"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "36675075"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
"text": "36675064"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Install (jose4j)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (jose4j)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (jose4j)). The supported version that is affected is 23.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (jose4j)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (jose4j)). The supported version that is affected is 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (jose4j)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Install (jose4j)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14118V-23.4.2",
"P-14547V-24.1.0",
"P-14488V-23.1.0",
"P-11125V-46.6.4",
"P-14547V-23.4.0",
"P-11125V-46.6.5",
"P-14117V-23.4.1"
],
"known_not_affected": [
"P-14250V-23.4.0",
"P-14277V-23.4.0-23.4.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034023.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033772.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14118V-23.4.2",
"P-14547V-24.1.0",
"P-14488V-23.1.0",
"P-11125V-46.6.4",
"P-14547V-23.4.0",
"P-11125V-46.6.5",
"P-14117V-23.4.1"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14250V-23.4.0",
"P-14277V-23.4.0-23.4.4"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-14250V-23.4.0"
]
},
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
]
}
]
},
{
"cve": "CVE-2023-52425",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36324185"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "36613199"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "36324198"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36324177"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36324171"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36516325"
},
{
"system_name": "Oracle Bug ID of Oracle Outside In Technology",
"text": "36324217"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
"text": "36324200"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36324201"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36324168"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36324146"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36324159"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (LibExpat)). The supported version that is affected is 8.5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (LibExpat)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (LibExpat)). The supported version that is affected is 8.0.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (LibExpat)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Database Core (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (LibExpat)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (LibExpat)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (LibExpat)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (LibExpat)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (LibExpat)). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Oracle Linux (LibExpat)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (LibExpat)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14117V-23.4.0",
"P-9190V-8.1.2.7",
"P-8479V-8.3.0 and prior",
"P-9190V-8.1.2.6",
"P-14121V-23.4.0-23.4.3",
"P-14547V-24.1.0",
"P-1042V-12.2.1.4.0",
"P-14123V-24.1.0",
"P-14277V-23.4.0-23.4.4",
"P-8479V-8.0.36 and prior",
"P-9190V-8.0.8.1",
"P-14117V-24.1.0",
"P-2276V-8.5.7",
"P-14547V-23.4.0",
"P-14488V-23.4.0",
"P-13789V-8.0.8.0",
"P-14123V-23.4.0",
"P-9190V-8.1.1.1"
],
"known_not_affected": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0",
"P-2276V-8.5.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13789V-8.0.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032877.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032876.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.0",
"P-14117V-24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.0.36 and prior",
"P-8479V-8.3.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-24.1.0",
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034023.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14117V-23.4.0",
"P-9190V-8.1.2.7",
"P-8479V-8.3.0 and prior",
"P-9190V-8.1.2.6",
"P-14121V-23.4.0-23.4.3",
"P-14547V-24.1.0",
"P-1042V-12.2.1.4.0",
"P-14123V-24.1.0",
"P-14277V-23.4.0-23.4.4",
"P-8479V-8.0.36 and prior",
"P-9190V-8.0.8.1",
"P-14117V-24.1.0",
"P-2276V-8.5.7",
"P-14547V-23.4.0",
"P-14488V-23.4.0",
"P-13789V-8.0.8.0",
"P-14123V-23.4.0",
"P-9190V-8.1.1.1"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
]
}
]
},
{
"cve": "CVE-2023-52426",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "36613199"
},
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36324185"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "36324198"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36324177"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36324171"
},
{
"system_name": "Oracle Bug ID of Oracle Outside In Technology",
"text": "36324217"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
"text": "36324200"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36324146"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36324168"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36324201"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36324159"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (LibExpat)). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (LibExpat)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (LibExpat)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (LibExpat)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (LibExpat)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (LibExpat)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (LibExpat)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (LibExpat)). The supported version that is affected is 8.0.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (LibExpat)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (LibExpat)). The supported version that is affected is 8.5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Database Core (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14117V-23.4.0",
"P-8479V-8.3.0 and prior",
"P-9190V-8.1.2.7",
"P-14121V-23.4.0-23.4.3",
"P-9190V-8.1.2.6",
"P-14547V-24.1.0",
"P-1042V-12.2.1.4.0",
"P-14277V-23.4.0-23.4.4",
"P-8479V-8.0.36 and prior",
"P-14117V-24.1.0",
"P-9190V-8.0.8.1",
"P-2276V-8.5.7",
"P-14547V-23.4.0",
"P-14488V-23.4.0",
"P-13789V-8.0.8.0",
"P-9190V-8.1.1.1"
],
"known_not_affected": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.0.36 and prior",
"P-8479V-8.3.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.0",
"P-14117V-24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034023.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032876.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13789V-8.0.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032877.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0",
"P-2276V-8.5.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14117V-23.4.0",
"P-8479V-8.3.0 and prior",
"P-9190V-8.1.2.7",
"P-14121V-23.4.0-23.4.3",
"P-9190V-8.1.2.6",
"P-14547V-24.1.0",
"P-1042V-12.2.1.4.0",
"P-14277V-23.4.0-23.4.4",
"P-8479V-8.0.36 and prior",
"P-14117V-24.1.0",
"P-9190V-8.0.8.1",
"P-2276V-8.5.7",
"P-14547V-23.4.0",
"P-14488V-23.4.0",
"P-13789V-8.0.8.0",
"P-9190V-8.1.1.1"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-5(Oracle Database Core)V-19.3-19.23",
"P-5(Oracle Database Core)V-21.3-21.14"
]
}
]
},
{
"cve": "CVE-2023-52428",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36440088"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "36331225"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Nimbus JOSE+JWT)). Supported versions that are affected are 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1-4.5.0.1.3, 24.1.0.0.0 and 24.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Storage Service Integration (Nimbus JOSE+JWT)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0",
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031477.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-5363",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36278320"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Liquidity Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management as well as unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.7.0.0.0",
"P-13304V-14.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-5678",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "component_not_present",
"product_ids": [
"P-4379V-21.5.6"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "36278330"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36278320"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36278333"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Branch",
"text": "36278313"
},
{
"system_name": "Oracle Bug ID of Siebel CRM Deployment",
"text": "36213692"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36278306"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (OpenSSL)). Supported versions that are affected are 8.0.36 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench as well as unauthorized update, insert or delete access to some of MySQL Workbench accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (OpenSSL)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Branch. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch as well as unauthorized update, insert or delete access to some of Oracle Banking Branch accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Liquidity Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management as well as unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (OpenSSL)). Supported versions that are affected are 24.2 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (OpenSSL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (OpenSSL)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server as well as unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-4627V-8.0.36 and prior",
"P-14324V-14.7.0.0.0",
"P-1042V-12.2.1.4.0",
"P-13304V-14.7.0.0.0",
"P-9019V-24.2 and prior",
"P-14324V-14.4.0.0.0",
"P-14324V-14.6.0.0.0"
],
"known_not_affected": [
"P-4379V-21.5.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4627V-8.0.36 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-14324V-14.7.0.0.0",
"P-13304V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-14324V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9019V-24.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-4627V-8.0.36 and prior",
"P-14324V-14.7.0.0.0",
"P-1042V-12.2.1.4.0",
"P-13304V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-14324V-14.6.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-9019V-24.2 and prior"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.5.6"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The software is not affected because the vulnerable component is not in the product.",
"product_ids": [
"P-4379V-21.5.6"
]
}
]
},
{
"cve": "CVE-2023-5685",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36496069"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36772129"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Install (XNIO)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (XNIO)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14121V-23.4.0-23.4.3",
"P-14277V-23.4.0-23.4.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14277V-23.4.0-23.4.4",
"P-14121V-23.4.0-23.4.3"
]
}
]
},
{
"cve": "CVE-2023-5764",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
"text": "36215189"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Ansible)). Supported versions that are affected are 24.3 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14107V-24.3 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14107V-24.3 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032935.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14107V-24.3 and prior"
]
}
]
},
{
"cve": "CVE-2023-5981",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
"text": "36128232"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (GnuTLS)). Supported versions that are affected are 2.0.0.0.0 and 2.0.0.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Converged Charging System accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14565V-2.0.0.1.0",
"P-14565V-2.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
]
}
]
},
{
"cve": "CVE-2023-6004",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
"text": "36135641"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36135621"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36135626"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (libssh)). Supported versions that are affected are 2.0.0.0.0 and 2.0.0.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Converged Charging System accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)). Supported versions that are affected are 8.0.36 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (libssh)). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Cluster accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14565V-2.0.0.1.0",
"P-8479V-8.4.0 and prior",
"P-4627V-8.0.36 and prior",
"P-8479V-8.0.37 and prior",
"P-14565V-2.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.4.0 and prior",
"P-4627V-8.0.36 and prior",
"P-8479V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-8479V-8.4.0 and prior",
"P-4627V-8.0.36 and prior",
"P-8479V-8.0.37 and prior",
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
]
}
]
},
{
"cve": "CVE-2023-6129",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "component_not_present",
"product_ids": [
"P-4379V-21.5.6"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "36278330"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36278320"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36278333"
},
{
"system_name": "Oracle Bug ID of JD Edwards World Security",
"text": "36367751"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Branch",
"text": "36278313"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36278306"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Liquidity Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management as well as unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (OpenSSL)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Branch. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch as well as unauthorized update, insert or delete access to some of Oracle Banking Branch accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (OpenSSL)). Supported versions that are affected are 8.0.36 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench as well as unauthorized update, insert or delete access to some of MySQL Workbench accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (OpenSSL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)). The supported version that is affected is A9.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise JD Edwards World Security. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards World Security as well as unauthorized update, insert or delete access to some of JD Edwards World Security accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (OpenSSL)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server as well as unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-4627V-8.0.36 and prior",
"P-14324V-14.7.0.0.0",
"P-1042V-12.2.1.4.0",
"P-13304V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-4839V-A9.4",
"P-14324V-14.6.0.0.0"
],
"known_not_affected": [
"P-4379V-21.5.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-14324V-14.7.0.0.0",
"P-13304V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-14324V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4627V-8.0.36 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4839V-A9.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-4627V-8.0.36 and prior",
"P-14324V-14.7.0.0.0",
"P-1042V-12.2.1.4.0",
"P-13304V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-4839V-A9.4",
"P-14324V-14.6.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.5.6"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The software is not affected because the vulnerable component is not in the product.",
"product_ids": [
"P-4379V-21.5.6"
]
}
]
},
{
"cve": "CVE-2023-6597",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36627542"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36627526"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (Python)). Supported versions that are affected are 8.0.36 and prior. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Workbench executes to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Install (Python)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Network Analytics Data Director executes to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14547V-23.4.0",
"P-4627V-8.0.36 and prior",
"P-14547V-24.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4627V-8.0.36 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4627V-8.0.36 and prior",
"P-14547V-24.1.0",
"P-14547V-23.4.0"
]
}
]
},
{
"cve": "CVE-2023-6918",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
"text": "36135641"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36135621"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36135626"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)). Supported versions that are affected are 8.0.36 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (libssh)). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Cluster accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (libssh)). Supported versions that are affected are 2.0.0.0.0 and 2.0.0.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Converged Charging System accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14565V-2.0.0.1.0",
"P-8479V-8.4.0 and prior",
"P-4627V-8.0.36 and prior",
"P-8479V-8.0.37 and prior",
"P-14565V-2.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.4.0 and prior",
"P-4627V-8.0.36 and prior",
"P-8479V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-8479V-8.4.0 and prior",
"P-4627V-8.0.36 and prior",
"P-8479V-8.0.37 and prior",
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
]
}
]
},
{
"cve": "CVE-2024-0232",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
"text": "36487799"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
"text": "36487790"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "36509185"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Common fns (SQLite)). Supported versions that are affected are 6.0.1.0.0, 12.0.1.0.0-12.0.6.0.0 and 15.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Network Charging and Control executes to compromise Oracle Communications Network Charging and Control. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XML Publisher (SQLite)). The supported version that is affected is 8.59. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Common fns (SQLite)). Supported versions that are affected are 6.0.1.0.0, 12.0.1.0.0-12.0.6.0.0 and 15.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Convergent Charging Controller executes to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12985V-6.0.1.0.0",
"P-12985V-12.0.1.0.0-12.0.6.0.0",
"P-5085V-8.59",
"P-4623V-6.0.1.0.0",
"P-12985V-15.0.0.0.0",
"P-4623V-12.0.1.0.0-12.0.6.0.0",
"P-4623V-15.0.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4623V-6.0.1.0.0",
"P-4623V-12.0.1.0.0-12.0.6.0.0",
"P-4623V-15.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029085.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.59"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12985V-6.0.1.0.0",
"P-12985V-12.0.1.0.0-12.0.6.0.0",
"P-12985V-15.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-12985V-6.0.1.0.0",
"P-12985V-12.0.1.0.0-12.0.6.0.0",
"P-5085V-8.59",
"P-4623V-6.0.1.0.0",
"P-12985V-15.0.0.0.0",
"P-4623V-12.0.1.0.0-12.0.6.0.0",
"P-4623V-15.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-0397",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36627544"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the OML4Py (Python) component of Oracle Database Server. Supported versions that are affected are 21.3-21.14 and 23.4. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via HTTPS to compromise OML4Py (Python). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of OML4Py (Python). CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(OML4Py)V-21.3-21.14",
"P-5(OML4Py)V-23.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(OML4Py)V-23.4",
"P-5(OML4Py)V-21.3-21.14"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(OML4Py)V-23.4",
"P-5(OML4Py)V-21.3-21.14"
]
}
]
},
{
"cve": "CVE-2024-0450",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "36744058"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36627542"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36627526"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (Python)). Supported versions that are affected are 8.0.36 and prior. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Workbench executes to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Install (Python)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Network Analytics Data Director executes to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (Python)). The supported version that is affected is 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Automated Test Suite executes to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14488V-23.1.0",
"P-14547V-23.4.0",
"P-4627V-8.0.36 and prior",
"P-14547V-24.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4627V-8.0.36 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034023.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4627V-8.0.36 and prior",
"P-14547V-24.1.0",
"P-14488V-23.1.0",
"P-14547V-23.4.0"
]
}
]
},
{
"cve": "CVE-2024-0727",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "component_not_present",
"product_ids": [
"P-4379V-21.5.6"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "36278330"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36278320"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36278333"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Branch",
"text": "36278313"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36278306"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "36672559"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (OpenSSL)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server as well as unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (OpenSSL)). Supported versions that are affected are 8.0.36 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench as well as unauthorized update, insert or delete access to some of MySQL Workbench accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (OpenSSL)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Branch. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch as well as unauthorized update, insert or delete access to some of Oracle Banking Branch accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Liquidity Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management as well as unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (OpenSSL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (OpenSSL)). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-2025V-12.2.1.4.0",
"P-13304V-14.6.0.0.0",
"P-4627V-8.0.36 and prior",
"P-14324V-14.7.0.0.0",
"P-2025V-7.6.0.0.0",
"P-1042V-12.2.1.4.0",
"P-2025V-7.0.0.0.0",
"P-13304V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-14324V-14.6.0.0.0"
],
"known_not_affected": [
"P-4379V-21.5.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4627V-8.0.36 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-14324V-14.7.0.0.0",
"P-13304V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-14324V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.6.0.0.0",
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-14324V-14.5.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-4627V-8.0.36 and prior",
"P-14324V-14.7.0.0.0",
"P-1042V-12.2.1.4.0",
"P-13304V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-14324V-14.6.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.5.6"
]
},
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.6.0.0.0",
"P-2025V-7.0.0.0.0"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The software is not affected because the vulnerable component is not in the product.",
"product_ids": [
"P-4379V-21.5.6"
]
}
]
},
{
"cve": "CVE-2024-0853",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-619V-19.3-19.23",
"P-619V-21.3-21.14",
"P-4379V-21.5.6"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Spatial and Graph (curl)",
"text": "36269139"
},
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "36349698"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36349702"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Spatial and Graph (curl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (curl)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (curl)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1042V-12.2.1.4.0"
],
"known_not_affected": [
"P-619V-21.3-21.14",
"P-619V-19.3-19.23",
"P-4379V-21.5.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-619V-19.3-19.23",
"P-619V-21.3-21.14",
"P-4379V-21.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-619V-19.3-19.23",
"P-619V-21.3-21.14"
]
},
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-1042V-12.2.1.4.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.5.6"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-619V-19.3-19.23",
"P-619V-21.3-21.14",
"P-4379V-21.5.6"
]
}
]
},
{
"cve": "CVE-2024-20996",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "32416819"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21098",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36495970"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Multilingual Engine component of Oracle Database Server. Supported versions that are affected are 21.3-21.14 and 23.4. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise Multilingual Engine. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Multilingual Engine. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Multilingual Engine)V-21.3-21.14",
"P-5(Multilingual Engine)V-23.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Multilingual Engine)V-21.3-21.14",
"P-5(Multilingual Engine)V-23.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Multilingual Engine)V-21.3-21.14",
"P-5(Multilingual Engine)V-23.4"
]
}
]
},
{
"cve": "CVE-2024-21122",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Shared Components",
"text": "33099179"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HCM Shared Components, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Shared Components accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Shared Components accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8943V-9.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8943V-9.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-8943V-9.2"
]
}
]
},
{
"cve": "CVE-2024-21123",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "31062179"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the infrastructure where Oracle Database Core executes to compromise Oracle Database Core. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Database Core accessible data. CVSS 3.1 Base Score 2.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Oracle Database Core)V-19.3-19.23"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-19.3-19.23"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 2.3,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-19.3-19.23"
]
}
]
},
{
"cve": "CVE-2024-21125",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34929814"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36741880"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.34 and prior, 7.6.30 and prior, 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8479V-7.6.30 and prior",
"P-8479V-8.4.0 and prior",
"P-8479V-8.0.37 and prior",
"P-8479V-7.5.34 and prior",
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-7.6.30 and prior",
"P-8479V-8.4.0 and prior",
"P-8479V-8.0.37 and prior",
"P-8479V-7.5.34 and prior",
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8479V-7.6.30 and prior",
"P-8479V-8.4.0 and prior",
"P-8479V-8.0.37 and prior",
"P-8479V-7.5.34 and prior",
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21126",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36135828"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.23 and 21.3-21.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware. While the vulnerability is in Oracle Database Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Portable Clusterware. CVSS 3.1 Base Score 5.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Oracle Database Portable Clusterware)V-21.3-21.14",
"P-5(Oracle Database Portable Clusterware)V-19.3-19.23"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Portable Clusterware)V-21.3-21.14",
"P-5(Oracle Database Portable Clusterware)V-19.3-19.23"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Portable Clusterware)V-21.3-21.14",
"P-5(Oracle Database Portable Clusterware)V-19.3-19.23"
]
}
]
},
{
"cve": "CVE-2024-21127",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35352161"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21128",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Application Object Library",
"text": "35425247"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: APIs). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-510V-12.2.6-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-510V-12.2.6-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-510V-12.2.6-12.2.13"
]
}
]
},
{
"cve": "CVE-2024-21129",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35507223"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21130",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35560806"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21131",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "35651102"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Antonin B"
],
"organization": "NATO Cyber Security Centre (NCSC)"
}
],
"cve": "CVE-2024-21132",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Purchasing",
"text": "35729689"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Approvals). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Purchasing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Purchasing accessible data as well as unauthorized read access to a subset of Oracle Purchasing accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-502V-12.2.3-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-502V-12.2.3-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-502V-12.2.3-12.2.13"
]
}
]
},
{
"cve": "CVE-2024-21133",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Reports Developer",
"text": "35834623"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Servlet). Supported versions that are affected are 12.2.1.4.0 and 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data as well as unauthorized read access to a subset of Oracle Reports Developer accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-159V-12.2.1.19.0",
"P-159V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-159V-12.2.1.19.0",
"P-159V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-159V-12.2.1.19.0",
"P-159V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2024-21134",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35854919"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21135",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35904044"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Louis Wolfers"
],
"organization": "synacktiv"
},
{
"names": [
"Quentin Roland"
],
"organization": "synacktiv"
}
],
"cve": "CVE-2024-21136",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Office",
"text": "35938737"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11560V-19.0.5",
"P-11560V-22.0.0",
"P-11560V-23.0.1",
"P-11560V-20.0.3",
"P-11560V-20.0.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11560V-20.0.3",
"P-11560V-20.0.4",
"P-11560V-19.0.5",
"P-11560V-22.0.0",
"P-11560V-23.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027543.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11560V-20.0.3",
"P-11560V-20.0.4",
"P-11560V-19.0.5",
"P-11560V-22.0.0",
"P-11560V-23.0.1"
]
}
]
},
{
"cve": "CVE-2024-21137",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35945822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.35 and prior",
"P-8478V-8.2.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.35 and prior",
"P-8478V-8.2.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.35 and prior",
"P-8478V-8.2.0 and prior"
]
}
]
},
{
"cve": "CVE-2024-21138",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "35955679"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
}
]
},
{
"cve": "CVE-2024-21139",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35972383"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-7.6.0.0.0",
"P-2025V-7.0.0.0.0",
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.6.0.0.0",
"P-2025V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-2025V-7.6.0.0.0",
"P-2025V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-21140",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "36001890"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Khang Phan"
],
"organization": "Viettel Cyber Security"
}
],
"cve": "CVE-2024-21141",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "36538816"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.20. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.20"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.20"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034015.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.20"
]
}
]
},
{
"cve": "CVE-2024-21142",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36022885"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21143",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle iStore",
"text": "36050686"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-384V-12.2.3-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-384V-12.2.3-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-384V-12.2.3-12.2.13"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Yakov Shafranovich"
],
"organization": "Amazon Web Services"
}
],
"cve": "CVE-2024-21144",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "36067946"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle Java SE:8u411-perf"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Sergey Bylokhov"
],
"organization": "Amazon"
}
],
"cve": "CVE-2024-21145",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "36077821"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
}
]
},
{
"cve": "CVE-2024-21146",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Trade Management",
"text": "36085452"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-765V-12.2.3-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-765V-12.2.3-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-765V-12.2.3-12.2.13"
]
}
]
},
{
"cve": "CVE-2024-21147",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "36096470"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:11.0.23",
"P-856V-Oracle Java SE:8u411",
"P-856V-Oracle Java SE:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:20.3.14",
"P-856V-Oracle Java SE:22.0.1",
"P-856V-Oracle Java SE:8u411-perf",
"P-856V-Oracle GraalVM for JDK:22.0.1",
"P-856V-Oracle GraalVM for JDK:21.0.3",
"P-856V-Oracle GraalVM Enterprise Edition:21.3.10",
"P-856V-Oracle GraalVM for JDK:17.0.11",
"P-856V-Oracle Java SE:17.0.11"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Nguyen Quach Duy Anh"
]
}
],
"cve": "CVE-2024-21148",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Applications Framework",
"text": "36101207"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1472V-12.2.3-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1472V-12.2.3-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-1472V-12.2.3-12.2.13"
]
}
]
},
{
"cve": "CVE-2024-21149",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Enterprise Asset Management",
"text": "36101991"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Asset Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1142V-12.2.11-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1142V-12.2.11-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-1142V-12.2.11-12.2.13"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Ahmed Shah"
],
"organization": "Red Canari"
}
],
"cve": "CVE-2024-21150",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "36112035"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.8.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
}
]
},
{
"cve": "CVE-2024-21151",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Solaris",
"text": "36160465"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10006V-11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10006V-11"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031405.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.3,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-10006V-11"
]
}
]
},
{
"cve": "CVE-2024-21152",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Process Manufacturing Financials",
"text": "36170963"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Allocation Rules). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-736V-12.2.12-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-736V-12.2.12-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-736V-12.2.12-12.2.13"
]
}
]
},
{
"cve": "CVE-2024-21153",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Process Manufacturing Product Development",
"text": "36170989"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Product Development accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Product Development accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-744V-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-744V-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-744V-12.2.13"
]
}
]
},
{
"cve": "CVE-2024-21154",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Human Resources",
"text": "36793514"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5071V-9.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5071V-9.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5071V-9.2"
]
}
]
},
{
"cve": "CVE-2024-21155",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
"text": "35318923"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: User Interface). The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle ZFS Storage Appliance Kit, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle ZFS Storage Appliance Kit accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10026V-8.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10026V-8.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031405.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-10026V-8.8"
]
}
]
},
{
"cve": "CVE-2024-21157",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36319083"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.4.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.4.0 and prior"
]
}
]
},
{
"cve": "CVE-2024-21158",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "36336378"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.61",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2024-21159",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36342792"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
]
}
]
},
{
"cve": "CVE-2024-21160",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36343647"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Derek Schrock"
]
},
{
"names": [
"Stefano Brivio"
],
"organization": "Red Hat"
}
],
"cve": "CVE-2024-21161",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "36697399"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.20. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. Note: This vulnerability applies to Linux hosts only. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.20"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.20"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034015.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.20"
]
}
]
},
{
"cve": "CVE-2024-21162",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36356279"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21163",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36366621"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Syed Faraz Abrar (Faith)"
],
"organization": "Zellic working with Trend Micro Zero Day Initiative"
},
{
"names": [
"Zheyu Ma"
]
}
],
"cve": "CVE-2024-21164",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "36726730"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.20"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.20"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034015.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 2.5,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.20"
]
}
]
},
{
"cve": "CVE-2024-21165",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36423078"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 8.0.37 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21166",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36425219"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.36 and prior",
"P-8478V-8.3.0 and prior"
]
}
]
},
{
"cve": "CVE-2024-21167",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Trading Community",
"text": "36427002"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trading Community accessible data as well as unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1137V-12.2.3-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1137V-12.2.3-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-1137V-12.2.3-12.2.13"
]
}
]
},
{
"cve": "CVE-2024-21168",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "36427005"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.8.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11681V-Prior to 9.2.8.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.8.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.8.3"
]
}
]
},
{
"cve": "CVE-2024-21169",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Marketing",
"text": "36456403"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Partners). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data as well as unauthorized read access to a subset of Oracle Marketing accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-229V-12.2.3-12.2.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-229V-12.2.3-12.2.13"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-229V-12.2.3-12.2.13"
]
}
]
},
{
"cve": "CVE-2024-21170",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "36476195"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8576V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8576V-8.4.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"P-8576V-8.4.0 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Jie Liang"
],
"organization": "WingTecher Lab"
},
{
"names": [
"Jingzhou Fu"
],
"organization": "WingTecher Lab"
},
{
"names": [
"Zhiyong Wu"
],
"organization": "WingTecher Lab"
}
],
"cve": "CVE-2024-21171",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36479091"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21173",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36526369"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21174",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36533029"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Java VM)V-21.3-21.14",
"P-5(Java VM)V-23.4",
"P-5(Java VM)V-19.3-19.23"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Java VM)V-21.3-21.14",
"P-5(Java VM)V-23.4",
"P-5(Java VM)V-19.3-19.23"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.1,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Java VM)V-21.3-21.14",
"P-5(Java VM)V-23.4",
"P-5(Java VM)V-19.3-19.23"
]
}
]
},
{
"cve": "CVE-2024-21175",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36056359"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2024-21176",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36548687"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.4.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Jie Liang"
],
"organization": "WingTecher Lab"
},
{
"names": [
"Jingzhou Fu"
],
"organization": "WingTecher Lab"
},
{
"names": [
"Zhiyong Wu"
],
"organization": "WingTecher Lab"
}
],
"cve": "CVE-2024-21177",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36741923"
},
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36563773"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.34 and prior, 7.6.30 and prior, 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8479V-7.6.30 and prior",
"P-8479V-8.4.0 and prior",
"P-8479V-8.0.37 and prior",
"P-8479V-7.5.34 and prior",
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-7.6.30 and prior",
"P-8479V-8.4.0 and prior",
"P-8479V-8.0.37 and prior",
"P-8479V-7.5.34 and prior",
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8479V-7.6.30 and prior",
"P-8479V-8.4.0 and prior",
"P-8479V-8.0.37 and prior",
"P-8479V-7.5.34 and prior",
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21178",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "36565921"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.61",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2024-21179",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36571091"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.37 and prior",
"P-8478V-8.4.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.0 and prior",
"P-8478V-8.0.37 and prior"
]
}
]
},
{
"cve": "CVE-2024-21180",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "36620043"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.61",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Boogipop"
]
},
{
"names": [
"L0ne1y"
]
},
{
"names": [
"ruozhi"
]
},
{
"names": [
"WHOAMI"
]
},
{
"names": [
"yemoli"
]
}
],
"cve": "CVE-2024-21181",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36165892"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Boogipop"
]
},
{
"names": [
"J0hNs0N"
],
"organization": "Qianxin wuji Lab"
},
{
"names": [
"yemoli"
]
},
{
"names": [
"yulate"
]
}
],
"cve": "CVE-2024-21182",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36165903"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"ja00see"
]
},
{
"names": [
"L0ne1y"
]
}
],
"cve": "CVE-2024-21183",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36290241"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2024-21184",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36343856"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security. Successful attacks of this vulnerability can result in takeover of Oracle Database RDBMS Security. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Oracle Database RDBMS Security)V-19.3-19.23"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database RDBMS Security)V-19.3-19.23"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5(Oracle Database RDBMS Security)V-19.3-19.23"
]
}
]
},
{
"cve": "CVE-2024-21185",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "36808732"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38, 8.4.1 and 9.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.4.1",
"P-8478V-8.0.38",
"P-8478V-9.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.4.1",
"P-8478V-9.0.0",
"P-8478V-8.0.38"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.4.1",
"P-8478V-9.0.0",
"P-8478V-8.0.38"
]
}
]
},
{
"cve": "CVE-2024-21188",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "36403191"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot). Supported versions that are affected are 6.0.0.0.0 and 6.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Revenue Management and Billing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Revenue Management and Billing accessible data as well as unauthorized read access to a subset of Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-6.0.0.0.0",
"P-5322V-6.1.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-6.1.0.0.0",
"P-5322V-6.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032766.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5322V-6.1.0.0.0",
"P-5322V-6.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-21742",
"ids": [
{
"system_name": "Oracle Bug ID of Primavera Unifier",
"text": "36444258"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Integration (Apache James MIME4J)). Supported versions that are affected are 19.12.0-19.12.16, 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.13 and 23.12.0-23.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-19.12.0-19.12.16",
"P-10354V-23.12.0-23.12.6",
"P-10354V-21.12.0-21.12.17",
"P-10354V-22.12.0-22.12.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-21.12.0-21.12.17",
"P-10354V-22.12.0-22.12.13",
"P-10354V-19.12.0-19.12.16",
"P-10354V-23.12.0-23.12.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030446.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-21.12.0-21.12.17",
"P-10354V-22.12.0-22.12.13",
"P-10354V-19.12.0-19.12.16",
"P-10354V-23.12.0-23.12.6"
]
}
]
},
{
"cve": "CVE-2024-21892",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
"text": "36651175"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Node.js)). The supported version that is affected is 12.11.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications User Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11108V-12.11.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11108V-12.11.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033765.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11108V-12.11.0"
]
}
]
},
{
"cve": "CVE-2024-22019",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
"text": "36651175"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Node.js)). The supported version that is affected is 12.11.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications User Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11108V-12.11.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11108V-12.11.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033765.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11108V-12.11.0"
]
}
]
},
{
"cve": "CVE-2024-22025",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
"text": "36651175"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Node.js)). The supported version that is affected is 12.11.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications User Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11108V-12.11.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11108V-12.11.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033765.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11108V-12.11.0"
]
}
]
},
{
"cve": "CVE-2024-22201",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-9456V-Prior to 24.1.0"
]
},
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-5(Oracle Database Workload Manager)V-21.3-21.14"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36512977"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36651028"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "36651032"
},
{
"system_name": "Oracle Bug ID of Oracle Coherence",
"text": "36651023"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
"text": "36651045"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36386816"
},
{
"system_name": "Oracle Bug ID of Oracle REST Data Services",
"text": "36297651"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Eclipse Jetty)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle REST Data Services (component: ORDS (Eclipse Jetty)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Database Workload Manager (Jetty) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Third Party (Eclipse Jetty)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Eclipse Jetty)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Eclipse Jetty)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Eclipse Jetty)). Supported versions that are affected are 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Financial Services Compliance Studio. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6",
"P-14118V-23.4.2",
"P-2545V-12.2.1.4.0",
"P-11125V-46.6.4",
"P-2545V-14.1.1.0.0",
"P-11125V-46.6.5",
"P-14117V-23.4.2"
],
"known_not_affected": [
"P-5(Oracle Database Workload Manager)V-21.3-21.14",
"P-9456V-Prior to 24.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Workload Manager)V-21.3-21.14",
"P-9456V-Prior to 24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2545V-12.2.1.4.0",
"P-2545V-14.1.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032854.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6",
"P-14118V-23.4.2",
"P-2545V-12.2.1.4.0",
"P-11125V-46.6.4",
"P-2545V-14.1.1.0.0",
"P-11125V-46.6.5",
"P-14117V-23.4.2"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Workload Manager)V-21.3-21.14",
"P-9456V-Prior to 24.1.0"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-9456V-Prior to 24.1.0"
]
},
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-5(Oracle Database Workload Manager)V-21.3-21.14"
]
}
]
},
{
"cve": "CVE-2024-22234",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36344616"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Install (Spring Security)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-23.4.0-23.4.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-14277V-23.4.0-23.4.4"
]
}
]
},
{
"cve": "CVE-2024-22243",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-5759V-12.2.1.2"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Management Pack for Oracle GoldenGate",
"text": "36399674"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36603575"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36603484"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "36336214"
},
{
"system_name": "Oracle Bug ID of Oracle Identity Manager",
"text": "36543538"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "36768964"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Platform",
"text": "36774956"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Management Pack for Oracle GoldenGate product of Oracle GoldenGate (component: Monitor - Java Agent (Spring Framework)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Spring Framework)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core (Spring Framework)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform (Spring Framework)). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Signaling (Spring Framework)). The supported version that is affected is 23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9348V-11.3.1",
"P-13304V-14.5.0.0.0",
"P-9348V-11.3.2",
"P-9348V-11.3.0",
"P-14122V-23.4.3",
"P-1980V-12.2.1.4.0",
"P-13304V-14.6.0.0.0",
"P-5242V-14.1.1.0.0",
"P-4647V-12.2.1.4.0",
"P-5242V-12.2.1.4.0",
"P-13304V-14.7.0.0.0"
],
"known_not_affected": [
"P-5759V-12.2.1.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-4647V-12.2.1.4.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5759V-12.2.1.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13304V-14.5.0.0.0",
"P-13304V-14.6.0.0.0",
"P-13304V-14.7.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033760.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9348V-11.3.1",
"P-13304V-14.5.0.0.0",
"P-9348V-11.3.2",
"P-9348V-11.3.0",
"P-14122V-23.4.3",
"P-1980V-12.2.1.4.0",
"P-13304V-14.6.0.0.0",
"P-5242V-14.1.1.0.0",
"P-4647V-12.2.1.4.0",
"P-5242V-12.2.1.4.0",
"P-13304V-14.7.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5759V-12.2.1.2"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-5759V-12.2.1.2"
]
}
]
},
{
"cve": "CVE-2024-22257",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36451775"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "36451754"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
"text": "36451781"
},
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
"text": "36451792"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Spring Security)). Supported versions that are affected are 8.0.38 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Enterprise Monitor accessible data as well as unauthorized update, insert or delete access to some of MySQL Enterprise Monitor accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (Spring Security)). Supported versions that are affected are 7.4.1 and 7.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Spring Security)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (Spring Security)). Supported versions that are affected are 11.2.11 and 11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Insurance Policy Administration J2EE accessible data as well as unauthorized update, insert or delete access to some of Oracle Insurance Policy Administration J2EE accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14118V-23.4.2",
"P-8480V-8.0.38 and prior",
"P-4516V-7.4.1",
"P-5279V-11.2.11",
"P-4516V-7.4.2",
"P-5279V-11.3.0-11.3.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8480V-8.0.38 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4516V-7.4.1",
"P-4516V-7.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029115.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5279V-11.2.11",
"P-5279V-11.3.0-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"products": [
"P-14118V-23.4.2",
"P-8480V-8.0.38 and prior",
"P-4516V-7.4.1",
"P-5279V-11.2.11",
"P-4516V-7.4.2",
"P-5279V-11.3.0-11.3.2"
]
}
]
},
{
"cve": "CVE-2024-22259",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36603575"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "36768964"
},
{
"system_name": "Oracle Bug ID of Oracle Identity Manager",
"text": "36543538"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Platform",
"text": "36774956"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core (Spring Framework)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Signaling (Spring Framework)). The supported version that is affected is 23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform (Spring Framework)). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-14122V-23.4.3",
"P-9348V-11.3.0",
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033760.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-14122V-23.4.3",
"P-9348V-11.3.0",
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2024-22262",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-5760V-19.1.0.0.0-19.1.0.0.18"
]
},
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-14250V-23.4.1"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
"text": "36548631"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36603528"
},
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
"text": "36603547"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36603503"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Enterprise Case Management",
"text": "36603525"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
"text": "36603523"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36603501"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Platform",
"text": "36774956"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36603502"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36603499"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "36603477"
},
{
"system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
"text": "36603533"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Assortment Planning",
"text": "36603555"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "35906314"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
"text": "36603497"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Cash Management",
"text": "36603475"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
"text": "36603531"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36603575"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Branch",
"text": "36603473"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36603496"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "36603493"
},
{
"system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
"text": "36603494"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "36603491"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "36768964"
},
{
"system_name": "Oracle Bug ID of Oracle Identity Manager",
"text": "36543538"
},
{
"system_name": "Oracle Bug ID of Oracle FLEXCUBE Universal Banking",
"text": "36603519"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
"text": "36603539"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
"text": "36603559"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "36603512"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Credit Facilities Process Management",
"text": "36603479"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "36603521"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "36603520"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36603484"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
"text": "36603540"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
"text": "36603562"
},
{
"system_name": "Oracle Bug ID of Primavera Unifier",
"text": "36603584"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Origination",
"text": "36603485"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "36603463"
},
{
"system_name": "Oracle Bug ID of Primavera Gateway",
"text": "36603580"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Framework)). Supported versions that are affected are 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Spring Framework)). Supported versions that are affected are 8.0.7, 8.0.8, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Spring Framework)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Model Management and Governance accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Spring Framework)). The supported version that is affected is 8.0.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: General (Spring Framework)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Spring Framework)). Supported versions that are affected are 8.1.4 and 8.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Data Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Healthcare Data Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Core (Spring Framework)). Supported versions that are affected are 5.0.0-5.0.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Master Person Index accessible data as well as unauthorized access to critical data or complete access to all Oracle Healthcare Master Person Index accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (Spring Framework)). Supported versions that are affected are 11.2.11 and 11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration J2EE accessible data as well as unauthorized access to critical data or complete access to all Oracle Insurance Policy Administration J2EE accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Assortment Planning product of Oracle Retail Applications (component: Application Core (Spring Framework)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Assortment Planning. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail Assortment Planning accessible data as well as unauthorized access to critical data or complete access to all Oracle Retail Assortment Planning accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration Bugs (Spring Framework)). Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and 19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data as well as unauthorized access to critical data or complete access to all Oracle Retail Financial Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)). Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and 19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail Integration Bus accessible data as well as unauthorized access to critical data or complete access to all Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core (Spring Framework)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Spring Framework)). Supported versions that are affected are 19.12.0-19.12.19, 20.12.0-20.12.14 and 21.12.0-21.12.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data as well as unauthorized access to critical data or complete access to all Primavera Gateway accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (Spring Framework)). Supported versions that are affected are 22.12.0-22.12.13 and 23.12.0-23.12.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Signaling (Spring Framework)). The supported version that is affected is 23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform (Spring Framework)). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (Spring Framework)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Docupresentment IDS Server (Spring Framework)). Supported versions that are affected are 12.6.4 and 12.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Documaker accessible data as well as unauthorized access to critical data or complete access to all Oracle Documaker accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Spring Framework)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Spring Framework)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Spring Framework)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (Spring Framework)). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Data Analytics Function accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Data Analytics Function accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Orchestration (Spring Framework)). Supported versions that are affected are 12.0.0.4-12.0.0.8 and 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications BRM - Elastic Charging Engine accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System, Workbench (Spring Framework)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Common (Spring Framework)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Virtual Account Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Basic Config/Maintenances (Spring Framework)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Origination accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Origination accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Spring Framework)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Credit Facilities Process Management product of Oracle Financial Services Applications (component: Common (Spring Framework)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Credit Facilities Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Credit Facilities Process Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Credit Facilities Process Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Spring Framework)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Corporate Lending Process Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Corporate Lending Process Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Spring Framework)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Cash Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Cash Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Spring Framework)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Branch accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Branch accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Spring Framework)). Supported versions that are affected are 8.0.38 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Enterprise Monitor accessible data as well as unauthorized access to critical data or complete access to all MySQL Enterprise Monitor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Spring Framework)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Spring Framework)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications EAGLE Element Management System accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Spring Framework)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Behavior Detection Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Installer (Spring Framework)). Supported versions that are affected are 8.0.8.2.8, 8.1.1.1.18, 8.1.2.6.4 and 8.1.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Enterprise Case Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Enterprise Case Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14195V-14.4.0.0.0",
"P-10722V-15.0.3.1",
"P-1807V-19.0.1",
"P-14121V-23.4.0-23.4.3",
"P-8480V-8.0.38 and prior",
"P-13545V-8.0.8.2.8",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-14122V-23.4.3",
"P-14195V-14.7.0.0.0",
"P-9052V-14.7.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-5680V-8.0.7",
"P-14324V-14.7.0.0.0",
"P-5680V-8.0.8",
"P-9190V-8.0.8.1",
"P-5242V-12.2.1.4.0",
"P-9742V-15.0.0.0",
"P-1807V-14.1.3.2",
"P-13701V-14.7.0.0.0",
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6",
"P-9190V-8.1.1.1",
"P-13545V-8.1.1.1.18",
"P-14118V-23.4.2",
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9742V-12.0.0.4-12.0.0.8",
"P-13545V-8.1.2.7.3",
"P-9161V-8.2.0",
"P-14195V-14.5.0.0.0",
"P-9633V-11.3.2",
"P-1807V-15.0.3.1",
"P-5242V-14.1.1.0.0",
"P-10605V-20.12.0-20.12.14",
"P-13701V-14.6.0.0.0",
"P-13487V-14.5.0.0.0",
"P-1788V-15.0.3",
"P-14325V-14.6.0.0.0",
"P-13703V-14.6.0.0.0",
"P-5477V-12.6.4",
"P-13789V-8.0.8.0",
"P-14324V-14.6.0.0.0",
"P-10722V-19.0.1",
"P-1788V-16.0.3",
"P-14195V-14.6.0.0.0",
"P-14489V-24.2.0",
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6",
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-13701V-14.4.0.0.0",
"P-13701V-14.5.0.0.0",
"P-1980V-12.2.1.4.0",
"P-9052V-14.5.0.0.0",
"P-13487V-14.6.0.0.0",
"P-13703V-14.5.0.0.0",
"P-5279V-11.3.0-11.3.2",
"P-10354V-23.12.0-23.12.6",
"P-14123V-23.4.0",
"P-9348V-11.3.1",
"P-14324V-14.5.0.0.0",
"P-9348V-11.3.2",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-9348V-11.3.0",
"P-9161V-8.1.4",
"P-8575V-5.0.0-5.0.9",
"P-10605V-19.12.0-19.12.19",
"P-5279V-11.2.11",
"P-11125V-46.6.4",
"P-13545V-8.1.2.6.4",
"P-10722V-14.1.3.2",
"P-11125V-46.6.5",
"P-10722V-16.0.3",
"P-14117V-23.4.2",
"P-1807V-16.0.3",
"P-9052V-14.6.0.0.0",
"P-14277V-23.4.0-23.4.4",
"P-13487V-14.7.0.0.0",
"P-10605V-21.12.0-21.12.12",
"P-10354V-22.12.0-22.12.13",
"P-13304V-14.7.0.0.0",
"P-5477V-12.7.1"
],
"known_not_affected": [
"P-14250V-23.4.1",
"P-5760V-19.1.0.0.0-19.1.0.0.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032854.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-5680V-8.0.7",
"P-5680V-8.0.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031528.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13789V-8.0.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032877.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5760V-19.1.0.0.0-19.1.0.0.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9161V-8.1.4",
"P-8575V-5.0.0-5.0.9",
"P-9161V-8.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031684.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5279V-11.2.11",
"P-5279V-11.3.0-11.3.2",
"P-5477V-12.6.4",
"P-5477V-12.7.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10722V-15.0.3.1",
"P-10722V-19.0.1",
"P-1807V-19.0.1",
"P-1807V-15.0.3.1",
"P-1788V-16.0.3",
"P-1788V-15.0.3",
"P-10722V-14.1.3.2",
"P-10722V-16.0.3",
"P-1807V-14.1.3.2",
"P-1807V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027543.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10605V-20.12.0-20.12.14",
"P-10605V-21.12.0-21.12.12",
"P-10354V-22.12.0-22.12.13",
"P-10605V-19.12.0-19.12.19",
"P-10354V-23.12.0-23.12.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030446.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033760.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0",
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14195V-14.4.0.0.0",
"P-14195V-14.6.0.0.0",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13701V-14.4.0.0.0",
"P-13701V-14.5.0.0.0",
"P-14195V-14.7.0.0.0",
"P-9052V-14.7.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-14324V-14.7.0.0.0",
"P-9052V-14.5.0.0.0",
"P-13487V-14.6.0.0.0",
"P-13703V-14.5.0.0.0",
"P-13701V-14.7.0.0.0",
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-14195V-14.5.0.0.0",
"P-9052V-14.6.0.0.0",
"P-13487V-14.7.0.0.0",
"P-13701V-14.6.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13304V-14.7.0.0.0",
"P-14325V-14.6.0.0.0",
"P-13703V-14.6.0.0.0",
"P-14324V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14489V-24.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033759.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9742V-12.0.0.4-12.0.0.8",
"P-9742V-15.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029087.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8480V-8.0.38 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-23.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033772.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032876.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13545V-8.1.1.1.18",
"P-13545V-8.0.8.2.8",
"P-13545V-8.1.2.6.4",
"P-13545V-8.1.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032811.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-14195V-14.4.0.0.0",
"P-10722V-15.0.3.1",
"P-1807V-19.0.1",
"P-14121V-23.4.0-23.4.3",
"P-8480V-8.0.38 and prior",
"P-13545V-8.0.8.2.8",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-14122V-23.4.3",
"P-14195V-14.7.0.0.0",
"P-9052V-14.7.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-5680V-8.0.7",
"P-14324V-14.7.0.0.0",
"P-5680V-8.0.8",
"P-9190V-8.0.8.1",
"P-5242V-12.2.1.4.0",
"P-9742V-15.0.0.0",
"P-1807V-14.1.3.2",
"P-13701V-14.7.0.0.0",
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6",
"P-9190V-8.1.1.1",
"P-13545V-8.1.1.1.18",
"P-14118V-23.4.2",
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9742V-12.0.0.4-12.0.0.8",
"P-13545V-8.1.2.7.3",
"P-9161V-8.2.0",
"P-14195V-14.5.0.0.0",
"P-9633V-11.3.2",
"P-1807V-15.0.3.1",
"P-5242V-14.1.1.0.0",
"P-10605V-20.12.0-20.12.14",
"P-13701V-14.6.0.0.0",
"P-13487V-14.5.0.0.0",
"P-1788V-15.0.3",
"P-14325V-14.6.0.0.0",
"P-13703V-14.6.0.0.0",
"P-5477V-12.6.4",
"P-13789V-8.0.8.0",
"P-14324V-14.6.0.0.0",
"P-10722V-19.0.1",
"P-1788V-16.0.3",
"P-14195V-14.6.0.0.0",
"P-14489V-24.2.0",
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6",
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-13701V-14.4.0.0.0",
"P-13701V-14.5.0.0.0",
"P-1980V-12.2.1.4.0",
"P-9052V-14.5.0.0.0",
"P-13487V-14.6.0.0.0",
"P-13703V-14.5.0.0.0",
"P-5279V-11.3.0-11.3.2",
"P-14123V-23.4.0",
"P-9348V-11.3.1",
"P-14324V-14.5.0.0.0",
"P-9348V-11.3.2",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-9348V-11.3.0",
"P-9161V-8.1.4",
"P-8575V-5.0.0-5.0.9",
"P-10605V-19.12.0-19.12.19",
"P-5279V-11.2.11",
"P-11125V-46.6.4",
"P-13545V-8.1.2.6.4",
"P-10722V-14.1.3.2",
"P-11125V-46.6.5",
"P-10722V-16.0.3",
"P-14117V-23.4.2",
"P-1807V-16.0.3",
"P-9052V-14.6.0.0.0",
"P-14277V-23.4.0-23.4.4",
"P-13487V-14.7.0.0.0",
"P-10605V-21.12.0-21.12.12",
"P-13304V-14.7.0.0.0",
"P-5477V-12.7.1"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5760V-19.1.0.0.0-19.1.0.0.18"
]
},
{
"cvss_v3": {
"baseScore": 4.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-10354V-22.12.0-22.12.13",
"P-10354V-23.12.0-23.12.6"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14250V-23.4.1"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-5760V-19.1.0.0.0-19.1.0.0.18"
]
},
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-14250V-23.4.1"
]
}
]
},
{
"cve": "CVE-2024-23635",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
"text": "36304479"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (AntiSamy)). The supported version that is affected is 11.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Policy Administration J2EE, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Insurance Policy Administration J2EE accessible data as well as unauthorized read access to a subset of Oracle Insurance Policy Administration J2EE accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5279V-11.2.11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5279V-11.2.11"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5279V-11.2.11"
]
}
]
},
{
"cve": "CVE-2024-23672",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-11528V-3.0.6",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
"text": "36680767"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
"text": "36680756"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "36705339"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36680774"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "36680740"
},
{
"system_name": "Oracle Bug ID of Graph Server and Client",
"text": "36680781"
},
{
"system_name": "Oracle Bug ID of Oracle Big Data Spatial and Graph",
"text": "36680749"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "36680759"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "36785491"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench, Platform Services, Content Acquisition System (Apache Tomcat)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Apache Tomcat)). Supported versions that are affected are 8.0.38 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Security (Apache Tomcat)). The supported version that is affected is 12.11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications User Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Tomcat)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (Apache Tomcat)). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Big Data Spatial and Graph (component: Big Data Graph (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Patches (Apache Tomcat)). Supported versions that are affected are 8.6.0.4-8.6.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Tomcat)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9633V-11.3.2",
"P-8480V-8.0.38 and prior",
"P-10899V-8.6.0.4-8.6.0.6",
"P-11108V-12.11.3",
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-14276V-8.1.2.5",
"P-14489V-24.2.0",
"P-14276V-8.1.2.6"
],
"known_not_affected": [
"P-14069V-22.4.7 and prior",
"P-11528V-3.0.6",
"P-14069V-23.4.2 and prior",
"P-14069V-24.1.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-11528V-3.0.6",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8480V-8.0.38 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11108V-12.11.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033765.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14489V-24.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033759.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.4-8.6.0.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3035470.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9633V-11.3.2",
"P-8480V-8.0.38 and prior",
"P-10899V-8.6.0.4-8.6.0.6",
"P-11108V-12.11.3",
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-14276V-8.1.2.5",
"P-14489V-24.2.0",
"P-14276V-8.1.2.6"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14069V-22.4.7 and prior",
"P-11528V-3.0.6",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-11528V-3.0.6",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
]
},
{
"cve": "CVE-2024-23807",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-5760V-19.1.0.0.0-19.1.0.0.18",
"P-5760V-21.3-21.14.0.0.0"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach",
"text": "36754759"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "36754738"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
"text": "36754771"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "36754761"
},
{
"system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
"text": "36754775"
},
{
"system_name": "Oracle Bug ID of Oracle Communications ASAP",
"text": "36754735"
},
{
"system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
"text": "36754746"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Basel Regulatory Capital Basic",
"text": "36754758"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
"text": "36754736"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "36754755"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications ASAP product of Oracle Communications Applications (component: Security (Apache Xerces-C++)). The supported version that is affected is 7.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications ASAP. Successful attacks of this vulnerability can result in takeover of Oracle Communications ASAP. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Apache Xerces-C++)). Supported versions that are affected are 8.1.1 and 8.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic product of Oracle Financial Services Applications (component: Platform (Apache Xerces-C++)). Supported versions that are affected are 8.0.7.3 and 8.0.8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Basel Regulatory Capital Basic. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Basel Regulatory Capital Basic. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach product of Oracle Financial Services Applications (component: Platform (Apache Xerces-C++)). Supported versions that are affected are 8.0.7.3 and 8.0.8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Apache Xerces-C++)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.6 and 8.1.2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Apache Xerces-C++)). The supported version that is affected is 8.0.8.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: General (Apache Xerces-C++)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Platform (Apache Xerces-C++)). Supported versions that are affected are 12.0.0.4.0-12.0.0.8.0 and 15.0.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Security (Apache Xerces-C++)). Supported versions that are affected are 12.11.3 and 12.11.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository. Successful attacks of this vulnerability can result in takeover of Oracle Communications User Data Repository. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Patches (Apache Xerces-C++)). Supported versions that are affected are 8.6.0.4-8.6.0.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9450V-8.0.7.3",
"P-9450V-8.0.8.3",
"P-11108V-12.11.3",
"P-2260V-7.4",
"P-9612V-8.0.8.3",
"P-9612V-8.0.7.3",
"P-2136V-12.0.0.4.0-12.0.0.8.0",
"P-10899V-8.6.0.4-8.6.0.8",
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-2136V-15.0.0.0.0",
"P-11108V-12.11.4",
"P-9190V-8.0.8.1",
"P-13789V-8.0.8.0",
"P-9190V-8.1.1.1"
],
"known_not_affected": [
"P-5760V-21.3-21.14.0.0.0",
"P-5760V-19.1.0.0.0-19.1.0.0.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2260V-7.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029082.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.1.1",
"P-5680V-8.1.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031528.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9612V-8.0.8.3",
"P-9612V-8.0.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032260.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9450V-8.0.7.3",
"P-9450V-8.0.8.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033171.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032876.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13789V-8.0.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032877.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5760V-19.1.0.0.0-19.1.0.0.18",
"P-5760V-21.3-21.14.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2136V-12.0.0.4.0-12.0.0.8.0",
"P-2136V-15.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029083.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11108V-12.11.4",
"P-11108V-12.11.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033765.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.4-8.6.0.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=3035470.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9450V-8.0.7.3",
"P-9450V-8.0.8.3",
"P-11108V-12.11.3",
"P-2260V-7.4",
"P-9612V-8.0.8.3",
"P-9612V-8.0.7.3",
"P-2136V-12.0.0.4.0-12.0.0.8.0",
"P-10899V-8.6.0.4-8.6.0.8",
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-2136V-15.0.0.0.0",
"P-11108V-12.11.4",
"P-9190V-8.0.8.1",
"P-13789V-8.0.8.0",
"P-9190V-8.1.1.1"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5760V-19.1.0.0.0-19.1.0.0.18",
"P-5760V-21.3-21.14.0.0.0"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-5760V-19.1.0.0.0-19.1.0.0.18",
"P-5760V-21.3-21.14.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-23897",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36508930"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "36508920"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36508922"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36508929"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36508925"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Jenkins)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Jenkins)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Automated Test Suite Framework (Jenkins)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Jenkins)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (Jenkins)). The supported version that is affected is 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14488V-23.1.0",
"P-14118V-23.4.2",
"P-14277V-23.4.0-23.4.4",
"P-14121V-23.4.0-23.4.3",
"P-14123V-23.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034023.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14118V-23.4.2",
"P-14277V-23.4.0-23.4.4",
"P-14121V-23.4.0-23.4.3",
"P-14488V-23.1.0",
"P-14123V-23.4.0"
]
}
]
},
{
"cve": "CVE-2024-23898",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36508930"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "36508920"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36508922"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36508929"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36508925"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Jenkins)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Jenkins)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (Jenkins)). The supported version that is affected is 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Jenkins)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Automated Test Suite Framework (Jenkins)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14488V-23.1.0",
"P-14118V-23.4.2",
"P-14277V-23.4.0-23.4.4",
"P-14121V-23.4.0-23.4.3",
"P-14123V-23.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034023.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14118V-23.4.2",
"P-14277V-23.4.0-23.4.4",
"P-14121V-23.4.0-23.4.3",
"P-14488V-23.1.0",
"P-14123V-23.4.0"
]
}
]
},
{
"cve": "CVE-2024-23944",
"ids": [
{
"system_name": "Oracle Bug ID of Primavera Unifier",
"text": "36444315"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (Apache ZooKeeper)). Supported versions that are affected are 19.12.0-19.12.16, 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.13 and 23.12.0-23.12.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-19.12.0-19.12.16",
"P-10354V-23.12.0-23.12.6",
"P-10354V-21.12.0-21.12.17",
"P-10354V-22.12.0-22.12.13"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-21.12.0-21.12.17",
"P-10354V-22.12.0-22.12.13",
"P-10354V-19.12.0-19.12.16",
"P-10354V-23.12.0-23.12.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030446.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.1,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-21.12.0-21.12.17",
"P-10354V-22.12.0-22.12.13",
"P-10354V-19.12.0-19.12.16",
"P-10354V-23.12.0-23.12.6"
]
}
]
},
{
"cve": "CVE-2024-24549",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-11528V-3.0.6",
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
"text": "36680756"
},
{
"system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
"text": "36680767"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36680774"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "36705339"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "36680740"
},
{
"system_name": "Oracle Bug ID of Graph Server and Client",
"text": "36680781"
},
{
"system_name": "Oracle Bug ID of Oracle Big Data Spatial and Graph",
"text": "36680749"
},
{
"system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
"text": "36680759"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "36785491"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Apache Tomcat)). Supported versions that are affected are 8.0.38 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Big Data Spatial and Graph (component: Big Data Graph (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (Apache Tomcat)). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Tomcat)). Supported versions that are affected are 46.6.4 and 46.6.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Security (Apache Tomcat)). The supported version that is affected is 12.11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications User Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Tomcat)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench, Platform Services, Content Acquisition System (Apache Tomcat)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Patches (Apache Tomcat)). Supported versions that are affected are 8.6.0.4-8.6.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9633V-11.3.2",
"P-8480V-8.0.38 and prior",
"P-10899V-8.6.0.4-8.6.0.6",
"P-11108V-12.11.3",
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-14276V-8.1.2.5",
"P-14489V-24.2.0",
"P-14276V-8.1.2.6"
],
"known_not_affected": [
"P-11528V-3.0.6",
"P-14069V-22.4.7 and prior",
"P-14069V-23.4.2 and prior",
"P-14069V-24.1.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8480V-8.0.38 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11528V-3.0.6",
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14489V-24.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033759.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11125V-46.6.4",
"P-11125V-46.6.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11108V-12.11.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033765.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.4-8.6.0.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3035470.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9633V-11.3.2",
"P-8480V-8.0.38 and prior",
"P-10899V-8.6.0.4-8.6.0.6",
"P-11108V-12.11.3",
"P-11125V-46.6.4",
"P-11125V-46.6.5",
"P-14276V-8.1.2.5",
"P-14489V-24.2.0",
"P-14276V-8.1.2.6"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11528V-3.0.6",
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-11528V-3.0.6",
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
]
},
{
"cve": "CVE-2024-24795",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "36736528"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
"text": "36736524"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (Apache HTTP Server)). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache HTTP Server)). Supported versions that are affected are 5.5.0-5.5.21 and 6.0.0-6.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.21",
"P-14597V-6.0.0-6.0.4",
"P-14489V-24.2.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14489V-24.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033759.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029086.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21",
"P-14489V-24.2.0"
]
}
]
},
{
"cve": "CVE-2024-24815",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Deposits and Lines of Credit Servicing",
"text": "36400490"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Deposits and Lines of Credit Servicing product of Oracle Financial Services Applications (component: Web UI (CKEditor)). The supported version that is affected is 2.12.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Deposits and Lines of Credit Servicing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Deposits and Lines of Credit Servicing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Deposits and Lines of Credit Servicing accessible data as well as unauthorized read access to a subset of Oracle Banking Deposits and Lines of Credit Servicing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13928V-2.12.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13928V-2.12.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031550.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13928V-2.12.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-24816",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Deposits and Lines of Credit Servicing",
"text": "36400490"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Deposits and Lines of Credit Servicing product of Oracle Financial Services Applications (component: Web UI (CKEditor)). The supported version that is affected is 2.12.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Deposits and Lines of Credit Servicing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Deposits and Lines of Credit Servicing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Deposits and Lines of Credit Servicing accessible data as well as unauthorized read access to a subset of Oracle Banking Deposits and Lines of Credit Servicing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13928V-2.12.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13928V-2.12.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031550.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13928V-2.12.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-25062",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-14250V-23.4.1"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "36417029"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "36417014"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36417048"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36417039"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36417032"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
"text": "36417033"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "36417013"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (libxml2)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libxml2)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libxml2)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Common (libxml2)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (libxml2)). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libxml2)). Supported versions that are affected are 8.0.36 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-23.4.0-23.4.4",
"P-8479V-8.4.0 and prior",
"P-13487V-14.7.0.0.0",
"P-14121V-23.4.0-23.4.3",
"P-8479V-8.0.37 and prior",
"P-4627V-8.0.36 and prior",
"P-1042V-12.2.1.4.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
],
"known_not_affected": [
"P-14250V-23.4.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-23.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033772.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.4.0 and prior",
"P-8479V-8.0.37 and prior",
"P-4627V-8.0.36 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031934.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14277V-23.4.0-23.4.4",
"P-8479V-8.4.0 and prior",
"P-13487V-14.7.0.0.0",
"P-14121V-23.4.0-23.4.3",
"P-8479V-8.0.37 and prior",
"P-4627V-8.0.36 and prior",
"P-1042V-12.2.1.4.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14250V-23.4.1"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-14250V-23.4.1"
]
}
]
},
{
"cve": "CVE-2024-2511",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "36781399"
},
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36703489"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Virtual Account Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Database Core (OpenSSL) component of Oracle Database Server. The supported version that is affected is 23.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Database Core (OpenSSL). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Core (OpenSSL). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13487V-14.5.0.0.0",
"P-5(Oracle Database Core)V-23.4",
"P-13487V-14.7.0.0.0",
"P-13487V-14.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-23.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13487V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-23.4"
]
}
]
},
{
"cve": "CVE-2024-25710",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36502354"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "36354261"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Cash Management",
"text": "36354184"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "36483093"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Branch",
"text": "36354181"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
"text": "36735887"
},
{
"system_name": "Oracle Bug ID of Oracle FLEXCUBE Investor Servicing",
"text": "36354258"
},
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
"text": "36354333"
},
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "36354255"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "36354376"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36354230"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Origination",
"text": "36354198"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36632585"
},
{
"system_name": "Oracle Bug ID of Oracle Analytics Desktop",
"text": "36503577"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
"text": "36354315"
},
{
"system_name": "Oracle Bug ID of Oracle NoSQL Database",
"text": "36354337"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36354196"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
"text": "36354226"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "36354267"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "36354388"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "36354224"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36354287"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Credit Facilities Process Management",
"text": "36354188"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "36354187"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36354229"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36354227"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Apache Commons Compress)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Apache Commons Compress)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Essbase Web Platform (Apache Commons Compress)). The supported version that is affected is 21.5.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Essbase executes to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Essbase. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure Code (Apache Commons Compress)). Supported versions that are affected are 14.5.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle FLEXCUBE Investor Servicing executes to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Investor Servicing. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)). Supported versions that are affected are 8.0.7, 8.0.8, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Financial Services Analytical Applications Infrastructure executes to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Apache Commons Compress)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Financial Services Behavior Detection Platform executes to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Commons Compress)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Financial Services Model Management and Governance executes to compromise Oracle Financial Services Model Management and Governance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR CLI (Apache Commons Compress)). Supported versions that are affected are 8.1.4 and 8.2.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Healthcare Data Repository executes to compromise Oracle Healthcare Data Repository. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (Apache Commons Compress)). Supported versions that are affected are 11.2.11 and 11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Insurance Policy Administration J2EE executes to compromise Oracle Insurance Policy Administration J2EE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle NoSQL Database (component: Administration (Apache Commons Compress)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Apache Commons Compress)). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache Commons Compress)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Fusion Client (Apache Commons Compress)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Retail Predictive Application Server executes to compromise Oracle Retail Predictive Application Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Install (Apache Commons Compress)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Analytics Server (Apache Commons Compress)). Supported versions that are affected are Prior to 7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Analytics Desktop executes to compromise Oracle Analytics Desktop. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Analytics Desktop. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Commons Compress)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (Apache Commons Compress)). The supported version that is affected is 23.4.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Unified Data Repository executes to compromise Oracle Communications Cloud Native Core Unified Data Repository. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Apache Commons Compress)). Supported versions that are affected are 24.1.0 and 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Apache Commons Compress)). The supported version that is affected is 23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Exposure Function executes to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Basic Config/Maintenances (Apache Commons Compress)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Origination executes to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Apache Commons Compress)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Liquidity Management executes to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Credit Facilities Process Management product of Oracle Financial Services Applications (component: Common (Apache Commons Compress)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Credit Facilities Process Management executes to compromise Oracle Banking Credit Facilities Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Credit Facilities Process Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache Commons Compress)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Corporate Lending Process Management executes to compromise Oracle Banking Corporate Lending Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Apache Commons Compress)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Cash Management executes to compromise Oracle Banking Cash Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Apache Commons Compress)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Branch executes to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Apache Commons Compress)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Repository Function executes to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14195V-14.4.0.0.0",
"P-9099V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-1823V-15.0.3",
"P-14122V-23.4.3",
"P-14195V-14.7.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-5680V-8.0.7",
"P-14324V-14.7.0.0.0",
"P-5680V-8.0.8",
"P-9190V-8.0.8.1",
"P-5242V-12.2.1.4.0",
"P-13701V-14.7.0.0.0",
"P-14276V-8.1.2.5",
"P-9190V-8.1.1.1",
"P-14276V-8.1.2.6",
"P-14118V-23.4.2",
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-5085V-8.59",
"P-1823V-16.0.3",
"P-9161V-8.2.0",
"P-14195V-14.5.0.0.0",
"P-14125V-24.1.0",
"P-2025V-Prior to 7.8.0",
"P-5242V-14.1.1.0.0",
"P-13701V-14.6.0.0.0",
"P-14325V-14.6.0.0.0",
"P-5085V-8.61",
"P-13703V-14.6.0.0.0",
"P-5085V-8.60",
"P-14324V-14.6.0.0.0",
"P-14125V-23.4.0",
"P-14277V-23.4.0",
"P-14195V-14.6.0.0.0",
"P-1696V-12.2.1.4.0",
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-13701V-14.4.0.0.0",
"P-13701V-14.5.0.0.0",
"P-9099V-14.5.0.0.0",
"P-4379V-21.5.6",
"P-13703V-14.5.0.0.0",
"P-5279V-11.3.0-11.3.2",
"P-14123V-23.4.0",
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-9161V-8.1.4",
"P-14119V-23.4.1",
"P-5279V-11.2.11",
"P-14117V-23.4.2",
"P-13304V-14.7.0.0.0"
],
"known_not_affected": [
"P-13373V-1.4",
"P-13373V-1.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5",
"P-4379V-21.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14195V-14.4.0.0.0",
"P-14325V-14.5.0.0.0",
"P-9099V-14.7.0.0.0",
"P-14195V-14.6.0.0.0",
"P-14195V-14.5.0.0.0",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13701V-14.4.0.0.0",
"P-13701V-14.5.0.0.0",
"P-14195V-14.7.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-9099V-14.5.0.0.0",
"P-14324V-14.7.0.0.0",
"P-13701V-14.6.0.0.0",
"P-13304V-14.7.0.0.0",
"P-14325V-14.6.0.0.0",
"P-13703V-14.5.0.0.0",
"P-13703V-14.6.0.0.0",
"P-13701V-14.7.0.0.0",
"P-14324V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-5680V-8.0.7",
"P-5680V-8.0.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031528.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032876.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9161V-8.1.4",
"P-9161V-8.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031684.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5279V-11.2.11",
"P-5279V-11.3.0-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.59",
"P-5085V-8.61",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0",
"P-1696V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027543.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-Prior to 7.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14119V-23.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033758.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14125V-24.1.0",
"P-14125V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033771.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033760.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14195V-14.4.0.0.0",
"P-9099V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-1823V-15.0.3",
"P-14122V-23.4.3",
"P-14195V-14.7.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-5680V-8.0.7",
"P-14324V-14.7.0.0.0",
"P-5680V-8.0.8",
"P-9190V-8.0.8.1",
"P-5242V-12.2.1.4.0",
"P-13701V-14.7.0.0.0",
"P-14276V-8.1.2.5",
"P-9190V-8.1.1.1",
"P-14276V-8.1.2.6",
"P-14118V-23.4.2",
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-5085V-8.59",
"P-1823V-16.0.3",
"P-9161V-8.2.0",
"P-14195V-14.5.0.0.0",
"P-14125V-24.1.0",
"P-2025V-Prior to 7.8.0",
"P-5242V-14.1.1.0.0",
"P-13701V-14.6.0.0.0",
"P-14325V-14.6.0.0.0",
"P-5085V-8.61",
"P-13703V-14.6.0.0.0",
"P-5085V-8.60",
"P-14324V-14.6.0.0.0",
"P-14125V-23.4.0",
"P-14277V-23.4.0",
"P-14195V-14.6.0.0.0",
"P-1696V-12.2.1.4.0",
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-13701V-14.4.0.0.0",
"P-13701V-14.5.0.0.0",
"P-9099V-14.5.0.0.0",
"P-4379V-21.5.6",
"P-13703V-14.5.0.0.0",
"P-5279V-11.3.0-11.3.2",
"P-14123V-23.4.0",
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-9161V-8.1.4",
"P-14119V-23.4.1",
"P-5279V-11.2.11",
"P-14117V-23.4.2",
"P-13304V-14.7.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13373V-1.4",
"P-13373V-1.5"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5"
]
}
]
},
{
"cve": "CVE-2024-26130",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36618145"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36618143"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36618144"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36618142"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36618150"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
"text": "36618151"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Cryptography)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (Cryptography)). Supported versions that are affected are 5.1 and 5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Install (Cryptography)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Cryptography)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Automated Test Suite (Cryptography)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Cryptography)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10761V-5.1",
"P-14118V-23.4.2",
"P-14277V-23.4.0-23.4.4",
"P-14117V-23.4.0",
"P-10761V-5.2",
"P-14547V-24.1.0",
"P-14117V-24.1.0",
"P-14547V-23.4.0",
"P-14123V-23.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10761V-5.1",
"P-10761V-5.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033757.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.0",
"P-14117V-24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-10761V-5.1",
"P-14118V-23.4.2",
"P-14277V-23.4.0-23.4.4",
"P-14117V-23.4.0",
"P-10761V-5.2",
"P-14547V-24.1.0",
"P-14117V-24.1.0",
"P-14547V-23.4.0",
"P-14123V-23.4.0"
]
}
]
},
{
"cve": "CVE-2024-26308",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_not_in_execute_path",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36502354"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "36354261"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Cash Management",
"text": "36354184"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "36483093"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Branch",
"text": "36354181"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "36365614"
},
{
"system_name": "Oracle Bug ID of Oracle FLEXCUBE Investor Servicing",
"text": "36354258"
},
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
"text": "36354333"
},
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "36354255"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "36354376"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36354230"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Origination",
"text": "36354198"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "36632585"
},
{
"system_name": "Oracle Bug ID of Oracle Analytics Desktop",
"text": "36503577"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
"text": "36354315"
},
{
"system_name": "Oracle Bug ID of Oracle NoSQL Database",
"text": "36354337"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "36156016"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36354196"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
"text": "36354226"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "36354267"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "36354388"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "36354224"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36354287"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Credit Facilities Process Management",
"text": "36354188"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "36354187"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36354229"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36354227"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Apache Commons Compress)). Supported versions that are affected are 24.1.0 and 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Apache Commons Compress)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Repository Function executes to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Apache Commons Compress)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Apache Commons Compress)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Essbase Web Platform (Apache Commons Compress)). The supported version that is affected is 21.5.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Essbase executes to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Essbase. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure Code (Apache Commons Compress)). Supported versions that are affected are 14.5.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle FLEXCUBE Investor Servicing executes to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Investor Servicing. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)). Supported versions that are affected are 8.0.7, 8.0.8, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Financial Services Analytical Applications Infrastructure executes to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Apache Commons Compress)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Financial Services Behavior Detection Platform executes to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Commons Compress)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Financial Services Model Management and Governance executes to compromise Oracle Financial Services Model Management and Governance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR CLI (Apache Commons Compress)). Supported versions that are affected are 8.1.4 and 8.2.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Healthcare Data Repository executes to compromise Oracle Healthcare Data Repository. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (Apache Commons Compress)). Supported versions that are affected are 11.2.11 and 11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Insurance Policy Administration J2EE executes to compromise Oracle Insurance Policy Administration J2EE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle NoSQL Database (component: Administration (Apache Commons Compress)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Apache Commons Compress)). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache Commons Compress)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Server (Apache Commons Compress)). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Fusion Client (Apache Commons Compress)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Retail Predictive Application Server executes to compromise Oracle Retail Predictive Application Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Install (Apache Commons Compress)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Analytics Server (Apache Commons Compress)). Supported versions that are affected are Prior to 7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Analytics Desktop executes to compromise Oracle Analytics Desktop. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Analytics Desktop. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Commons Compress)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Jython)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Apache Commons Compress)). The supported version that is affected is 23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Exposure Function executes to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Basic Config/Maintenances (Apache Commons Compress)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Origination executes to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Apache Commons Compress)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Liquidity Management executes to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Credit Facilities Process Management product of Oracle Financial Services Applications (component: Common (Apache Commons Compress)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Credit Facilities Process Management executes to compromise Oracle Banking Credit Facilities Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Credit Facilities Process Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Apache Commons Compress)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Branch executes to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Apache Commons Compress)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Cash Management executes to compromise Oracle Banking Cash Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache Commons Compress)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Corporate Lending Process Management executes to compromise Oracle Banking Corporate Lending Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14195V-14.4.0.0.0",
"P-9099V-14.7.0.0.0",
"P-5085(Web Server)V-8.60",
"P-5085(Web Server)V-8.61",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-1823V-15.0.3",
"P-14122V-23.4.3",
"P-14195V-14.7.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-5680V-8.0.7",
"P-14324V-14.7.0.0.0",
"P-5680V-8.0.8",
"P-9190V-8.0.8.1",
"P-5242V-12.2.1.4.0",
"P-13701V-14.7.0.0.0",
"P-14276V-8.1.2.5",
"P-9190V-8.1.1.1",
"P-14276V-8.1.2.6",
"P-14118V-23.4.2",
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-1823V-16.0.3",
"P-9161V-8.2.0",
"P-14195V-14.5.0.0.0",
"P-14125V-24.1.0",
"P-2025V-Prior to 7.8.0",
"P-5085(OpenSearch)V-8.60",
"P-5085(OpenSearch)V-8.61",
"P-5242V-14.1.1.0.0",
"P-13701V-14.6.0.0.0",
"P-14325V-14.6.0.0.0",
"P-13703V-14.6.0.0.0",
"P-14324V-14.6.0.0.0",
"P-14125V-23.4.0",
"P-14277V-23.4.0",
"P-14195V-14.6.0.0.0",
"P-1696V-12.2.1.4.0",
"P-5085(OpenSearch)V-8.59",
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-13701V-14.4.0.0.0",
"P-13701V-14.5.0.0.0",
"P-9099V-14.5.0.0.0",
"P-4379V-21.5.6",
"P-13703V-14.5.0.0.0",
"P-5279V-11.3.0-11.3.2",
"P-14123V-23.4.0",
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-9161V-8.1.4",
"P-5279V-11.2.11",
"P-14117V-23.4.2",
"P-4647V-12.2.1.4.0",
"P-13304V-14.7.0.0.0",
"P-5085(Web Server)V-8.59"
],
"known_not_affected": [
"P-13373V-1.4",
"P-13373V-1.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14125V-24.1.0",
"P-14125V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033771.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5",
"P-4379V-21.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14195V-14.4.0.0.0",
"P-14325V-14.5.0.0.0",
"P-9099V-14.7.0.0.0",
"P-14195V-14.6.0.0.0",
"P-14195V-14.5.0.0.0",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13701V-14.4.0.0.0",
"P-14195V-14.7.0.0.0",
"P-13701V-14.5.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-9099V-14.5.0.0.0",
"P-14324V-14.7.0.0.0",
"P-13701V-14.6.0.0.0",
"P-13304V-14.7.0.0.0",
"P-14325V-14.6.0.0.0",
"P-13703V-14.5.0.0.0",
"P-13703V-14.6.0.0.0",
"P-13701V-14.7.0.0.0",
"P-14324V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-5680V-8.0.7",
"P-5680V-8.0.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031528.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032876.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9161V-8.1.4",
"P-9161V-8.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031684.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5279V-11.2.11",
"P-5279V-11.3.0-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032841.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085(OpenSearch)V-8.60",
"P-5085(OpenSearch)V-8.61",
"P-5085(Web Server)V-8.60",
"P-5085(Web Server)V-8.61",
"P-5085(OpenSearch)V-8.59",
"P-5085(Web Server)V-8.59"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032892.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-4647V-12.2.1.4.0",
"P-5242V-12.2.1.4.0",
"P-1696V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027543.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-Prior to 7.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030276.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033760.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14195V-14.4.0.0.0",
"P-9099V-14.7.0.0.0",
"P-5085(Web Server)V-8.60",
"P-5085(Web Server)V-8.61",
"P-14324V-14.4.0.0.0",
"P-13304V-14.5.0.0.0",
"P-1823V-15.0.3",
"P-14122V-23.4.3",
"P-14195V-14.7.0.0.0",
"P-14325V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-5680V-8.0.7",
"P-14324V-14.7.0.0.0",
"P-5680V-8.0.8",
"P-9190V-8.0.8.1",
"P-5242V-12.2.1.4.0",
"P-13701V-14.7.0.0.0",
"P-14276V-8.1.2.5",
"P-9190V-8.1.1.1",
"P-14276V-8.1.2.6",
"P-14118V-23.4.2",
"P-9190V-8.1.2.7",
"P-9190V-8.1.2.6",
"P-1823V-16.0.3",
"P-9161V-8.2.0",
"P-14195V-14.5.0.0.0",
"P-14125V-24.1.0",
"P-2025V-Prior to 7.8.0",
"P-5085(OpenSearch)V-8.60",
"P-5085(OpenSearch)V-8.61",
"P-5242V-14.1.1.0.0",
"P-13701V-14.6.0.0.0",
"P-14325V-14.6.0.0.0",
"P-13703V-14.6.0.0.0",
"P-14324V-14.6.0.0.0",
"P-14125V-23.4.0",
"P-14277V-23.4.0",
"P-14195V-14.6.0.0.0",
"P-1696V-12.2.1.4.0",
"P-5085(OpenSearch)V-8.59",
"P-5680V-8.1.1",
"P-5680V-8.1.2",
"P-13701V-14.4.0.0.0",
"P-13701V-14.5.0.0.0",
"P-9099V-14.5.0.0.0",
"P-4379V-21.5.6",
"P-13703V-14.5.0.0.0",
"P-5279V-11.3.0-11.3.2",
"P-14123V-23.4.0",
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14325V-14.5.0.0.0",
"P-9161V-8.1.4",
"P-5279V-11.2.11",
"P-14117V-23.4.2",
"P-4647V-12.2.1.4.0",
"P-13304V-14.7.0.0.0",
"P-5085(Web Server)V-8.59"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13373V-1.4",
"P-13373V-1.5"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
"product_ids": [
"P-13373V-1.4",
"P-13373V-1.5"
]
}
]
},
{
"cve": "CVE-2024-27316",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "36736528"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
"text": "36736524"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (Apache HTTP Server)). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache HTTP Server)). Supported versions that are affected are 5.5.0-5.5.21 and 6.0.0-6.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.21",
"P-14597V-6.0.0-6.0.4",
"P-14489V-24.2.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14489V-24.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033759.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029086.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-6.0.0-6.0.4",
"P-14597V-5.5.0-5.5.21",
"P-14489V-24.2.0"
]
}
]
},
{
"cve": "CVE-2024-27980",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GraalVM for JDK",
"text": "36523910"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.11, 21.0.3 and 22.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM for JDK as well as unauthorized update, insert or delete access to some of Oracle GraalVM for JDK accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
]
}
]
},
{
"cve": "CVE-2024-27982",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GraalVM for JDK",
"text": "36523910"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.11, 21.0.3 and 22.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM for JDK as well as unauthorized update, insert or delete access to some of Oracle GraalVM for JDK accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
]
}
]
},
{
"cve": "CVE-2024-27983",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GraalVM for JDK",
"text": "36523910"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "36010587"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.11, 21.0.3 and 22.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM for JDK as well as unauthorized update, insert or delete access to some of Oracle GraalVM for JDK accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-4781V-Prior to 9.2.8.2",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.8.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032893.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031998.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.8.2"
]
},
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13497V-Oracle GraalVM for JDK:21.0.3",
"P-13497V-Oracle GraalVM for JDK:17.0.11",
"P-13497V-Oracle GraalVM for JDK:22.0.1"
]
}
]
},
{
"cve": "CVE-2024-28182",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
"text": "36754859"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
"text": "36060123"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (Nghttp2)). Supported versions that are affected are 4.1.0, 4.2.0, 9.2.0 and 9.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Session Border Controller. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Nghttp2)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10750V-4.1.0",
"P-10750V-9.2.0",
"P-10750V-4.2.0",
"P-10750V-9.3.0",
"P-14119V-23.4.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10750V-4.1.0",
"P-10750V-4.2.0",
"P-10750V-9.2.0",
"P-10750V-9.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032665.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14119V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033758.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-10750V-4.1.0",
"P-10750V-4.2.0",
"P-10750V-9.2.0",
"P-10750V-9.3.0"
]
},
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-14119V-23.4.2"
]
}
]
},
{
"cve": "CVE-2024-28752",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Platform",
"text": "36764318"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "36766162"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "36766163"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
"text": "36766159"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Endeca Integration (Apache CXF)). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Apache CXF)). The supported version that is affected is 23.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: General (Apache CXF)). Supported versions that are affected are 9.0.0-9.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Session Report Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Session Report Manager accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Security (Apache CXF)). Supported versions that are affected are 9.0.0-9.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Element Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Element Manager accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0",
"P-10770V-9.0.0-9.0.3",
"P-14119V-23.4.1",
"P-11052V-9.0.0-9.0.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14119V-23.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033758.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.0-9.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034257.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.0-9.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034508.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0",
"P-10770V-9.0.0-9.0.3",
"P-14119V-23.4.1",
"P-11052V-9.0.0-9.0.3"
]
}
]
},
{
"cve": "CVE-2024-28757",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Outside In Technology",
"text": "36324217"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (LibExpat)). The supported version that is affected is 8.5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2276V-8.5.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2276V-8.5.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2276V-8.5.7"
]
}
]
},
{
"cve": "CVE-2024-28849",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36441818"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Configuration (follow-redirects)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
]
}
]
},
{
"cve": "CVE-2024-29025",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "36628190"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36496198"
},
{
"system_name": "Oracle Bug ID of Oracle FLEXCUBE Universal Banking",
"text": "36628207"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "36728281"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
"text": "36628203"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Branch",
"text": "36628159"
},
{
"system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
"text": "36628226"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "36628177"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36628200"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "36628184"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Platform",
"text": "36628174"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36628186"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
"text": "36628197"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Credit Facilities Process Management",
"text": "36628164"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
"text": "36628187"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "36628192"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
"text": "36628170"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "36488758"
},
{
"system_name": "Oracle Bug ID of Oracle Coherence",
"text": "36628182"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Netty)). The supported version that is affected is 23.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle TimesTen In-Memory Database (component: TimesTen Install (Netty)). Supported versions that are affected are 22.1.1.1.0-22.1.1.24.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle TimesTen In-Memory Database. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (Netty)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer Platform (Netty)). The supported version that is affected is 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Install (Netty)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (Netty)). Supported versions that are affected are 2.0.0.0.0 and 2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Netty)). The supported version that is affected is 23.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Netty)). The supported version that is affected is 23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Netty)). The supported version that is affected is 23.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Netty)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Install (Netty)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Netty)). Supported versions that are affected are 14.4.0.0.0, 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Branch. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Credit Facilities Process Management product of Oracle Financial Services Applications (component: Common (Netty)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Credit Facilities Process Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Credit Facilities Process Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Netty)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Security (Netty)). The supported version that is affected is 2.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Platform. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Common (Netty)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Third Party (Netty)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (Netty)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14121V-23.4.0-23.4.3",
"P-14547V-24.1.0",
"P-2545V-14.1.1.0.0",
"P-14324V-14.4.0.0.0",
"P-14250V-23.4.1",
"P-13304V-14.5.0.0.0",
"P-14122V-23.4.3",
"P-9052V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-14324V-14.7.0.0.0",
"P-14117V-24.1.0",
"P-9052V-14.5.0.0.0",
"P-1870V-22.1.1.1.0-22.1.1.24.0",
"P-14547V-23.4.0",
"P-13703V-14.5.0.0.0",
"P-13487V-14.6.0.0.0",
"P-14123V-23.4.0",
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14118V-23.4.2",
"P-14117V-23.4.0",
"P-2545V-12.2.1.4.0",
"P-9178V-2.4.0.0.0",
"P-14565V-2.0.0.1.0",
"P-9052V-14.6.0.0.0",
"P-14277V-23.4.0-23.4.4",
"P-13487V-14.7.0.0.0",
"P-9633V-11.3.2",
"P-14565V-2.0.0.0.0",
"P-13304V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13703V-14.6.0.0.0",
"P-2283V-8.0.0",
"P-14324V-14.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033778.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1870V-22.1.1.1.0-22.1.1.24.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14324V-14.4.0.0.0",
"P-9052V-14.6.0.0.0",
"P-13304V-14.5.0.0.0",
"P-13487V-14.7.0.0.0",
"P-9052V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-14324V-14.7.0.0.0",
"P-9052V-14.5.0.0.0",
"P-13304V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13703V-14.5.0.0.0",
"P-13487V-14.6.0.0.0",
"P-13703V-14.6.0.0.0",
"P-14324V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2283V-8.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029087.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14565V-2.0.0.0.0",
"P-14565V-2.0.0.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032835.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033754.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033760.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-23.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033772.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-23.4.0",
"P-14117V-24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033762.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9178V-2.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031550.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2545V-12.2.1.4.0",
"P-2545V-14.1.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032937.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-14121V-23.4.0-23.4.3",
"P-14547V-24.1.0",
"P-2545V-14.1.1.0.0",
"P-14324V-14.4.0.0.0",
"P-14250V-23.4.1",
"P-13304V-14.5.0.0.0",
"P-14122V-23.4.3",
"P-9052V-14.7.0.0.0",
"P-13304V-14.6.0.0.0",
"P-14324V-14.7.0.0.0",
"P-14117V-24.1.0",
"P-9052V-14.5.0.0.0",
"P-14547V-23.4.0",
"P-13703V-14.5.0.0.0",
"P-13487V-14.6.0.0.0",
"P-14123V-23.4.0",
"P-14324V-14.5.0.0.0",
"P-13703V-14.7.0.0.0",
"P-14118V-23.4.2",
"P-14117V-23.4.0",
"P-2545V-12.2.1.4.0",
"P-9178V-2.4.0.0.0",
"P-14565V-2.0.0.1.0",
"P-9052V-14.6.0.0.0",
"P-14277V-23.4.0-23.4.4",
"P-13487V-14.7.0.0.0",
"P-9633V-11.3.2",
"P-14565V-2.0.0.0.0",
"P-13304V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13703V-14.6.0.0.0",
"P-2283V-8.0.0",
"P-14324V-14.6.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-1870V-22.1.1.1.0-22.1.1.24.0"
]
}
]
},
{
"cve": "CVE-2024-29041",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
"text": "36441818"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Configuration (follow-redirects)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033768.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14547V-24.1.0",
"P-14547V-23.4.0"
]
}
]
},
{
"cve": "CVE-2024-29131",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
"text": "36711732"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Party Management",
"text": "36711723"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36711735"
},
{
"system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
"text": "36711724"
},
{
"system_name": "Oracle Bug ID of Graph Server and Client",
"text": "36711737"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Commons Configuration)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Model Management and Governance executes to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Model Management and Governance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Commons Configuration)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Commons Configuration)). Supported versions that are affected are 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Compliance Studio executes to compromise Oracle Financial Services Compliance Studio. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Compliance Studio accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Security (Apache Commons Configuration)). Supported versions that are affected are 12.0.0.4-12.0.0.8 and 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications BRM - Elastic Charging Engine accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (Apache Commons Configuration)). The supported version that is affected is 2.7.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Banking Party Management executes to compromise Oracle Banking Party Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Party Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Party Management. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6",
"P-13929V-2.7.0.0.0",
"P-9742V-12.0.0.4-12.0.0.8",
"P-9742V-15.0.0.0",
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"known_not_affected": [
"P-14069V-22.4.7 and prior",
"P-14069V-23.4.2 and prior",
"P-14069V-24.1.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032854.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9742V-12.0.0.4-12.0.0.8",
"P-9742V-15.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029087.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13929V-2.7.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031550.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"products": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6",
"P-13929V-2.7.0.0.0",
"P-9742V-12.0.0.4-12.0.0.8",
"P-9742V-15.0.0.0",
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
]
},
{
"cve": "CVE-2024-29133",
"flags": [
{
"date": "2024-07-16T13:00:00-07:00",
"label": "vulnerable_code_cannot_be_controlled_by_adversary",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
],
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
"text": "36711732"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Party Management",
"text": "36711723"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "36711735"
},
{
"system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
"text": "36711724"
},
{
"system_name": "Oracle Bug ID of Graph Server and Client",
"text": "36711737"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Commons Configuration)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Commons Configuration)). Supported versions that are affected are 8.1.2.5 and 8.1.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Model Management and Governance executes to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Model Management and Governance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Commons Configuration)). Supported versions that are affected are 8.1.2.6 and 8.1.2.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Compliance Studio executes to compromise Oracle Financial Services Compliance Studio. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Compliance Studio accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Security (Apache Commons Configuration)). Supported versions that are affected are 12.0.0.4-12.0.0.8 and 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications BRM - Elastic Charging Engine accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (Apache Commons Configuration)). The supported version that is affected is 2.7.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Banking Party Management executes to compromise Oracle Banking Party Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Party Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Party Management. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6",
"P-13929V-2.7.0.0.0",
"P-9742V-12.0.0.4-12.0.0.8",
"P-9742V-15.0.0.0",
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"known_not_affected": [
"P-14069V-22.4.7 and prior",
"P-14069V-23.4.2 and prior",
"P-14069V-24.1.0 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033761.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=3032854.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9742V-12.0.0.4-12.0.0.8",
"P-9742V-15.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3029087.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13929V-2.7.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031550.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
},
{
"cvss_v3": {
"baseScore": 4.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"products": [
"P-14392V-8.1.2.7",
"P-14392V-8.1.2.6",
"P-13929V-2.7.0.0.0",
"P-9742V-12.0.0.4-12.0.0.8",
"P-9742V-15.0.0.0",
"P-14276V-8.1.2.5",
"P-14276V-8.1.2.6"
]
}
],
"threats": [
{
"category": "impact",
"date": "2024-07-16T13:00:00-07:00",
"details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
"product_ids": [
"P-14069V-22.4.7 and prior",
"P-14069V-24.1.0 and prior",
"P-14069V-23.4.2 and prior"
]
}
]
},
{
"cve": "CVE-2024-29203",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Application Express",
"text": "36155725"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Application Express (component: General (TinyMCE)). The supported version that is affected is 23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1348V-23.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1348V-23.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1348V-23.2"
]
}
]
},
{
"cve": "CVE-2024-2961",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
"text": "36735916"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (glibc)). The supported version that is affected is 23.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14119V-23.4.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14119V-23.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033758.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14119V-23.4.1"
]
}
]
},
{
"cve": "CVE-2024-29857",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
"text": "36631030"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "36577442"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Bouncy Castle Java Library)). Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1-4.5.0.1.3, 24.1.0.0.0 and 24.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Bouncy Castle Java Library)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12738V-12.2.1.4.0",
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031477.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12738V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-12738V-12.2.1.4.0",
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-29881",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Application Express",
"text": "36155725"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Application Express (component: General (TinyMCE)). The supported version that is affected is 23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1348V-23.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1348V-23.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1348V-23.2"
]
}
]
},
{
"cve": "CVE-2024-30171",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
"text": "36631030"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "36577442"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Bouncy Castle Java Library)). Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1-4.5.0.1.3, 24.1.0.0.0 and 24.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Bouncy Castle Java Library)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12738V-12.2.1.4.0",
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031477.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12738V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-12738V-12.2.1.4.0",
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-30172",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
"text": "36631030"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "36577442"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Bouncy Castle Java Library)). Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1-4.5.0.1.3, 24.1.0.0.0 and 24.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Bouncy Castle Java Library)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12738V-12.2.1.4.0",
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031477.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12738V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-12738V-12.2.1.4.0",
"P-2245V-4.5.0.1.1-4.5.0.1.3",
"P-2245V-24.1.0.0.0",
"P-2245V-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-2245V-24.2.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-32114",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "36736654"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Apache ActiveMQ)). Supported versions that are affected are 8.1.1 and 8.1.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Financial Services Analytical Applications Infrastructure executes to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5680V-8.1.1",
"P-5680V-8.1.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.1.1",
"P-5680V-8.1.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=3031528.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5680V-8.1.1",
"P-5680V-8.1.2"
]
}
]
},
{
"cve": "CVE-2024-34064",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
"text": "36755479"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Install (Jinja2)). Supported versions that are affected are 23.4.0 and 24.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data as well as unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033771.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
]
}
]
},
{
"cve": "CVE-2024-34069",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
"text": "36755503"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Install (Werkzeug)). Supported versions that are affected are 23.4.0 and 24.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033771.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14125V-23.4.0",
"P-14125V-24.1.0"
]
}
]
},
{
"cve": "CVE-2024-34447",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
"text": "36631030"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Bouncy Castle Java Library)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12738V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12738V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-12738V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2024-34459",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "36417048"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (libxml2)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1042V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=3030266.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-1042V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2024-4603",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "36781399"
},
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36703489"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database Core (OpenSSL) component of Oracle Database Server. The supported version that is affected is 23.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Database Core (OpenSSL). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Core (OpenSSL). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Virtual Account Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Oracle Database Core)V-23.4",
"P-13487V-14.5.0.0.0",
"P-13487V-14.7.0.0.0",
"P-13487V-14.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-23.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-23.4"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13487V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-4741",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "36781399"
},
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "36703489"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database Core (OpenSSL) component of Oracle Database Server. The supported version that is affected is 23.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Database Core (OpenSSL). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Core (OpenSSL). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Common (OpenSSL)). Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and 14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Banking Virtual Account Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Oracle Database Core)V-23.4",
"P-13487V-14.5.0.0.0",
"P-13487V-14.7.0.0.0",
"P-13487V-14.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Core)V-23.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3027813.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Core)V-23.4"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13487V-14.7.0.0.0",
"P-13487V-14.5.0.0.0",
"P-13487V-14.6.0.0.0"
]
}
]
},
{
"cve": "CVE-2024-6162",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "36771976"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "36766538"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Undertow)). Supported versions that are affected are 23.4.0-23.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Install (Undertow)). Supported versions that are affected are 23.4.0-23.4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14121V-23.4.0-23.4.3",
"P-14277V-23.4.0-23.4.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-23.4.0-23.4.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=3033755.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-23.4.0-23.4.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=3034256.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14277V-23.4.0-23.4.4",
"P-14121V-23.4.0-23.4.3"
]
}
]
}
]
}